Microsoft Sentinel
Cloud and workloads

Configure Fusion Rules

In brief

The page’s publication date and authoring metadata were updated, and several Fusion descriptions and scheduled analytics rule guidance were reworded for clarity, including the Customer-Managed Keys link text.

What Defender admins need to know

No administrator action is specified; use the updated guidance when reviewing Fusion configuration.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security engineer, I want to configure multistage attack detection rules so that analysts can more easily identify and respond to complex multistage threats with high accuracy. [!INCLUDE reference-to-feature-availability]

Microsoft Sentinel uses Fusion, a correlation engine based on scalable machine learning algorithms, to automatically detect multistage attacks by identifying combinations of anomalous behaviors and suspicious activities that are observed at various stages of the attack chain. Based on these discoveries,detected attack patterns, Microsoft Sentinel generates incidents that would otherwise be difficult to catch. These incidents comprise two or more alerts or activities. By design, these incidents are low-volume, high-fidelity, and high-severity.

Customized for your environment, this detection technology not only reduces false positive rates but can also detect attacks with limited or missing information.

Configure scheduled analytics rules for Fusion detections

Fusion detects scenario-based multistage attacks and emerging threats by using alerts generated by scheduled analytics rules. To get the most out of Microsoft Sentinel's Fusion capabilities, take the following steps to configure and enable these rules.

  1. Fusion for emerging threats uses alerts generated by any scheduled analytics rules that contain kill-chain (tactics) and entity mapping information. To ensure that Fusion can use analerts from a scheduled analytics rule's output to detect emerging threats:threats, verify the rule's entity mapping and tactics configuration:

    • Review entity mapping for these scheduled rules. Use the entity mapping configuration section to map parameters from your query results to Microsoft Sentinel-recognized entities. Because Fusion correlates alerts based on entities (such as user account or IP address), its ML algorithms can't perform alert matching without the entity information.