Microsoft Defender Threat Intelligence
General

Analyst Insights

In brief

The Analyst insights page was deleted. Its previous notice stated that Defender TI will be discontinued and merged into Microsoft Defender, with existing access available until August 1, 2026.

What Defender admins need to know

Defender TI administrators should track the planned retirement and the availability of the current experience through August 1, 2026.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

deleted file mode 100644

title: Microsoft Defender Threat Intelligence (Defender TI) Analyst insights description: Learn about the Microsoft Defender Threat Intelligence (Defender TI)'s Analyst insights feature. ms.topic: overview ms.date: 09/12/2025 ms.custom:

  • template-overview
  • cx-ti
  • cx-mdti

Analyst insights

In Microsoft Defender Threat Intelligence (Defender TI), the Analyst insights section provides you with quick insights about an artifact that might help determine your next step in an investigation. This section lists any insights that apply to the artifact, and insights that don't apply for extra visibility.

In the following example, you can quickly determine that the IP address is routable, hosts a web server, and had an open port within the past five days. Furthermore, the system displays rules that weren't triggered, which can be equally helpful when kick starting an investigation.

:::image type="content" source="/defender/threat-intelligence/media/analyst-insights.png" alt-text="Analyst insights screenshot." lightbox="/defender/threat-intelligence/media/analyst-insights.png":::

Analyst insight types and questions they can address

Analyst insight typesQuestions they can address
BlocklistedIs/When was the domain, host, or IP address blocklisted?
How many times has Defender TI blocklisted the domain, host, or IP address?
Registered and updatedHow many days, months, and years ago was the domain registered?
When was the domain WHOIS record updated?
Subdomain IP countHow many different IP addresses are associated with the subdomains of the domain?
New subdomain observationsWhen was the last time Microsoft observed a new subdomain for the domain in question?
Registered and resolvingDoes the domain queried exist?
Does the domain resolve to an IP address?
Number of domains sharing the WHOIS recordWhat other domains share the same WHOIS record?
Number of domains sharing the name serverWhat other domains share the same name server record?
Crawled by RiskIQWhen was this host or domain last crawled by Microsoft?
International domainIs the domain queried for an international domain name (IDN)?
Blocklisted by third partyIs this indicator blocklisted by a third party?
Tor exit node statusIs the IP address in questions associated with The Onion Router (Tor) network?
Open ports detectedWhen did Microsoft last port scan this IP address?
Proxy statusWhat is the proxy status of this indicator?
Host last observedIs the IP address in question internet accessible?
Hosts a web serverDoes the IP address have a Domain Name System (DNS) server that uses its resources to resolve the name into it for the appropriate web server?

See also