Microsoft Defender XDR
General

Entity Page Threat Intelligence

In brief

The documentation now explains the 0–100 reputation score, its Malicious, Suspicious, Neutral, and Unknown ranges, scoring inputs, and infrastructure data sources including passive DNS, port scans, web crawling, and reverse DNS.

What Defender admins need to know

Administrators and analysts can interpret entity reputation scores and infrastructure relationships more consistently. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Reputation

The reputation section provides a risk assessment for the entity based on Microsoft's detection rules and intelligence. Reputation scores help analysts quickly determine whether an entity is known to becategorized as malicious, suspicious, neutral, or benign.unknown and surface any prior malicious or suspicious activity tied to the entity.

Reputation appears as a numerical score from 0 to 100. Microsoft derives the score from proprietary data and machine learning rules—each assigned a High, Medium, or Low severity—that assess factors such as the top-level domain, hosting provider, name server, registrar, and TLS certificate characteristics. Assess these factors holistically: the combination of indicators, rather than any single one, predicts whether an entity is likely malicious. Hosts, domains, and IP addresses fall into the following categories based on their score:

ScoreCategoryDescription
75–100MaliciousConfirmed associations to known malicious infrastructure on Microsoft's blocklist, with matches to machine learning rules that detect suspicious activity.
50–74SuspiciousLikely associated with suspicious infrastructure based on matches to three or more machine learning rules.
25–49NeutralMatches at least two machine learning rules.
0–24UnknownReturned one or zero rule matches.

Attributed threat reports

Infrastructure relationships (IP addresses and domains)

For IP address and domain entities, the infrastructure relationships section draws on Microsoft's internet data—collected through passive DNS (PDNS), port scans, and web-crawling infrastructure—to reveal connected infrastructure and support infrastructure analysis. This section includes:

  • DNS records - Historical and current DNS resolution data.data, including reverse DNS, that shows which domains resolved to an IP address and the reverse over time.
  • WHOIS information - Domain registration details including registrant, dates, and registrar.
  • Host pairs - Relationships between hosts based on observed connections in web content.
  • Subdomains - Known subdomains associated with a domain.