Analyst Insights
In brief
The Analyst insights page was deleted. Its previous notice stated that Defender TI will be discontinued and merged into Microsoft Defender, with existing access available until August 1, 2026.
What Defender admins need to know
Defender TI administrators should track the planned retirement and the availability of the current experience through August 1, 2026.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
deleted file mode 100644
title: Microsoft Defender Threat Intelligence (Defender TI) Analyst insights
description: Learn about the Microsoft Defender Threat Intelligence (Defender TI)'s Analyst insights feature.
ms.topic: overview
ms.date: 09/12/2025
ms.custom:
template-overviewcx-ticx-mdti
Analyst insights
In Microsoft Defender Threat Intelligence (Defender TI), the Analyst insights section provides you with quick insights about an artifact that might help determine your next step in an investigation. This section lists any insights that apply to the artifact, and insights that don't apply for extra visibility.
In the following example, you can quickly determine that the IP address is routable, hosts a web server, and had an open port within the past five days. Furthermore, the system displays rules that weren't triggered, which can be equally helpful when kick starting an investigation.
:::image type="content" source="/defender/threat-intelligence/media/analyst-insights.png" alt-text="Analyst insights screenshot." lightbox="/defender/threat-intelligence/media/analyst-insights.png":::
Analyst insight types and questions they can address
See also
@@ -1,49 +0,0 @@-----title: Microsoft Defender Threat Intelligence (Defender TI) Analyst insights-description: Learn about the Microsoft Defender Threat Intelligence (Defender TI)'s Analyst insights feature.-ms.topic: overview-ms.date: 09/12/2025-ms.custom: -- template-overview-- cx-ti-- cx-mdti------# Analyst insights--> [!IMPORTANT]-> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)--In Microsoft Defender Threat Intelligence (Defender TI), the **Analyst insights** section provides you with quick insights about an artifact that might help determine your next step in an investigation. This section lists any insights that apply to the artifact, and insights that don't apply for extra visibility. --In the following example, you can quickly determine that the IP address is routable, hosts a web server, and had an open port within the past five days. Furthermore, the system displays rules that weren't triggered, which can be equally helpful when kick starting an investigation.--:::image type="content" source="/defender/threat-intelligence/media/analyst-insights.png" alt-text="Analyst insights screenshot." lightbox="/defender/threat-intelligence/media/analyst-insights.png":::--## Analyst insight types and questions they can address--|Analyst insight types|Questions they can address|-|---|---|-|Blocklisted|Is/When was the domain, host, or IP address blocklisted?|-||How many times has Defender TI blocklisted the domain, host, or IP address?|-|Registered and updated|How many days, months, and years ago was the domain registered?|-||When was the domain WHOIS record updated?|-|Subdomain IP count|How many different IP addresses are associated with the subdomains of the domain?|-|New subdomain observations|When was the last time Microsoft observed a new subdomain for the domain in question?|-|Registered and resolving|Does the domain queried exist?|-||Does the domain resolve to an IP address?|-|Number of domains sharing the WHOIS record|What other domains share the same WHOIS record?|-|Number of domains sharing the name server|What other domains share the same name server record?|-|Crawled by RiskIQ|When was this host or domain last crawled by Microsoft?|-|International domain|Is the domain queried for an international domain name (IDN)?|-|Blocklisted by third party|Is this indicator blocklisted by a third party?|-|Tor exit node status|Is the IP address in questions associated with The Onion Router (Tor) network?|-|Open ports detected|When did Microsoft last port scan this IP address?|-|Proxy status|What is the proxy status of this indicator?|-|Host last observed|Is the IP address in question internet accessible?|-|Hosts a web server|Does the IP address have a Domain Name System (DNS) server that uses its resources to resolve the name into it for the appropriate web server?|--### See also--- [Reputation scoring](reputation-scoring.md)-- [Using tags](using-tags.md) 