Gathering Vulnerability Intelligence
In brief
The tutorial page was deleted. Its notice stated that Defender TI will be discontinued and merged into Microsoft Defender, with existing customers retaining access until August 1, 2026.
What Defender admins need to know
Administrators should note the stated retirement date; no administrator task is specified in the diff.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
deleted file mode 100644
title: 'Tutorial: Gathering vulnerability intelligence using Microsoft Defender Threat Intelligence (Defender TI)'
description: Practice gathering vulnerability intelligence using Microsoft Defender Threat Intelligence (Defender TI).
ms.topic: tutorial
ms.date: 09/12/2025
ms.custom:
template-overviewcx-ticx-mdti
Tutorial: Gathering vulnerability intelligence
This tutorial walks you through how to perform several types of indicator searches to gather vulnerability intelligence using Microsoft Defender Threat Intelligence (Defender TI) in the Microsoft Defender portal.
Prerequisites
A Microsoft Entra ID or personal Microsoft account. Sign in or create an accountA Defender TI Premium license.
Disclaimer
Defender TI might include live, real-time observations and threat indicators, including malicious infrastructure and adversary-threat tooling. Any IP address and domain searches within Defender TI are safe to search. Microsoft shares online resources (for example, IP addresses, domain names) that are considered real threats posing a clear and present danger. We ask that you use their best judgment and minimize unnecessary risk while interacting with malicious systems when performing the following tutorial. Microsoft minimizes risks by defanging malicious IP addresses, hosts, and domains.
Before you begin
As the disclaimer states previously, suspicious and malicious indicators are defanged for your safety. Remove any brackets from IP addresses, domains, and hosts when searching in Defender TI. Don't search these indicators directly in your browser.
Open Defender TI in the Microsoft Defender portal
- Access the Defender portal and complete the Microsoft authentication process. Learn more about the Defender portal
Learn about Intel explorer home page features
Review the Intel explorer search bar options by selecting its drop-down menu.:::image type="content" source="/defender/threat-intelligence/media/tutorialVulnerabilityIntelSearchBar.png" alt-text="Tutorial Vulnerability Intel Search Bar." lightbox="/defender/threat-intelligence/media/tutorialVulnerabilityIntelSearchBar.png":::Scroll down and review the featured and recent articles in their respective sections. Learn more about Defender TI articles:::image type="content" source="/defender/threat-intelligence/media/intel-explorer.png" alt-text="ti Overview Home Page Chrome Screenshot." lightbox="/defender/threat-intelligence/media/intel-explorer.png":::
Perform indicator searches and gather vulnerability intelligence
SearchCVE-2020-1472in theIntel explorersearch bar, the select and review the associated Intel profileCVE-2020-1472 - Netlogon Elevation of Privilege vulnerability.:::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-netlogon-article.png" alt-text="Screentshot of the CVE-2020-1472 Netlogon vulnerability profile." lightbox="/defender/threat-intelligence/media/tutorial-vuln-netlogon-article.png":::Select the profile'sRelated articlestab then select the articleGraphican: Nylon Typhoon (NICKEL) Uses New Backdoor in Attacks Targeting Foreign Ministries.:::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-related-articles.png" alt-text="Tutorial Vulnerability Graphican article." lightbox="/defender/threat-intelligence/media/tutorial-vuln-related-articles.png":::Select this newly opened article'sPublic indicators. You should see the IP address 50.116.3[.]164 among the listed indicators.:::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-public-indicators.png" alt-text="Tutorial Vulnerability Graphican public indicators." lightbox="/defender/threat-intelligence/media/tutorial-vuln-public-indicators.png":::Navigate back to theIntel explorersearch bar and search50.116.3[.]164.Review the following results in theSummarytab:ReputationAnalyst insightsArticlesServicesResolutionsCertificatesProjects
:::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-ip-summary.png" alt-text="Tutorial Vulnerability Intel Ip Summary Tab." lightbox="/defender/threat-intelligence/media/tutorial-vuln-ip-summary.png":::You can also select and review the information in their respective tabs.Select theResolutionstab then selectpiwik.enpers[.]com.:::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-resolutions.png" alt-text="Tutorial Vulnerability Intel Domain Pivot." lightbox="/defender/threat-intelligence/media/tutorial-vuln-resolutions.png":::Review this domain's resolutions, WHOIS, certificates, subdomains, trackers, components, cookies, DNS, and reverse DNS data sets.:::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-piwik-resolutions.png" alt-text="Tutorial vulnerability intelligence domain resolutions review." lightbox="/defender/threat-intelligence/media/tutorial-vuln-piwik-resolutions.png"::::::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-piwik-whois.png" alt-text="Tutorial vulnerability intelligence domain WHOIS review." lightbox="/defender/threat-intelligence/media/tutorial-vuln-piwik-whois.png":::Perform the respective artifact searches from the previous steps. You could reference and use the different search options inIntel explorersearch bar dropdown menu.
Clean up resources
There are no resources to clean up in this section.
See also
@@ -1,94 +0,0 @@-----title: 'Tutorial: Gathering vulnerability intelligence using Microsoft Defender Threat Intelligence (Defender TI)'-description: Practice gathering vulnerability intelligence using Microsoft Defender Threat Intelligence (Defender TI).-ms.topic: tutorial-ms.date: 09/12/2025-ms.custom: -- template-overview-- cx-ti-- cx-mdti------# Tutorial: Gathering vulnerability intelligence--> [!IMPORTANT]-> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)--This tutorial walks you through how to perform several types of indicator searches to gather vulnerability intelligence using Microsoft Defender Threat Intelligence (Defender TI) in the Microsoft Defender portal.--## Prerequisites--- A Microsoft Entra ID or personal Microsoft account. [Sign in or create an account](https://signup.microsoft.com/)-- A Defender TI Premium license.-- > [!NOTE]- > Users without a Defender TI Premium license can still access our free Defender TI offering.--## Disclaimer--Defender TI might include live, real-time observations and threat indicators, including malicious infrastructure and adversary-threat tooling. Any IP address and domain searches within Defender TI are safe to search. Microsoft shares online resources (for example, IP addresses, domain names) that are considered real threats posing a clear and present danger. We ask that you use their best judgment and minimize unnecessary risk while interacting with malicious systems when performing the following tutorial. Microsoft minimizes risks by defanging malicious IP addresses, hosts, and domains.--## Before you begin--As the disclaimer states previously, suspicious and malicious indicators are defanged for your safety. Remove any brackets from IP addresses, domains, and hosts when searching in Defender TI. Don't search these indicators directly in your browser.--## Open Defender TI in the Microsoft Defender portal--1. Access the [Defender portal](https://security.microsoft.com/) and complete the Microsoft authentication process. [Learn more about the Defender portal](/defender-xdr/microsoft-365-defender-portal)-2. Navigate to **Threat intelligence** > **Intel explorer**.--## Learn about Intel explorer home page features--1. Review the Intel explorer search bar options by selecting its drop-down menu.-- :::image type="content" source="/defender/threat-intelligence/media/tutorialVulnerabilityIntelSearchBar.png" alt-text="Tutorial Vulnerability Intel Search Bar." lightbox="/defender/threat-intelligence/media/tutorialVulnerabilityIntelSearchBar.png":::--2. Scroll down and review the featured and recent articles in their respective sections. [Learn more about Defender TI articles](what-is-microsoft-defender-threat-intelligence-defender-ti.md#articles)-- :::image type="content" source="/defender/threat-intelligence/media/intel-explorer.png" alt-text="ti Overview Home Page Chrome Screenshot." lightbox="/defender/threat-intelligence/media/intel-explorer.png":::--## Perform indicator searches and gather vulnerability intelligence--1. Search *CVE-2020-1472* in the **Intel explorer** search bar, the select and review the associated Intel profile *CVE-2020-1472 - Netlogon Elevation of Privilege vulnerability*.-- :::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-netlogon-article.png" alt-text="Screentshot of the CVE-2020-1472 Netlogon vulnerability profile." lightbox="/defender/threat-intelligence/media/tutorial-vuln-netlogon-article.png":::--2. Select the profile's **Related articles** tab then select the article *Graphican: Nylon Typhoon (NICKEL) Uses New Backdoor in Attacks Targeting Foreign Ministries*.-- :::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-related-articles.png" alt-text="Tutorial Vulnerability Graphican article." lightbox="/defender/threat-intelligence/media/tutorial-vuln-related-articles.png":::--3. Select this newly opened article's **Public indicators**. You should see the IP address 50.116.3[.]164 among the listed indicators.-- :::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-public-indicators.png" alt-text="Tutorial Vulnerability Graphican public indicators." lightbox="/defender/threat-intelligence/media/tutorial-vuln-public-indicators.png":::-4. Navigate back to the **Intel explorer** search bar and search *50.116.3[.]164*.-5. Review the following results in the **Summary** tab:- - Reputation- - Analyst insights- - Articles- - Services- - Resolutions- - Certificates- - Projects--- :::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-ip-summary.png" alt-text="Tutorial Vulnerability Intel Ip Summary Tab." lightbox="/defender/threat-intelligence/media/tutorial-vuln-ip-summary.png":::-- You can also select and review the information in their respective tabs.--6. Select the **Resolutions** tab then select *piwik.enpers[.]com*.-- :::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-resolutions.png" alt-text="Tutorial Vulnerability Intel Domain Pivot." lightbox="/defender/threat-intelligence/media/tutorial-vuln-resolutions.png":::--7. Review this domain's resolutions, WHOIS, certificates, subdomains, trackers, components, cookies, DNS, and reverse DNS data sets.-- :::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-piwik-resolutions.png" alt-text="Tutorial vulnerability intelligence domain resolutions review." lightbox="/defender/threat-intelligence/media/tutorial-vuln-piwik-resolutions.png":::-- :::image type="content" source="/defender/threat-intelligence/media/tutorial-vuln-piwik-whois.png" alt-text="Tutorial vulnerability intelligence domain WHOIS review." lightbox="/defender/threat-intelligence/media/tutorial-vuln-piwik-whois.png":::-10. Perform the respective artifact searches from the previous steps. You could reference and use the different search options in **Intel explorer** search bar dropdown menu.--## Clean up resources--There are no resources to clean up in this section.--### See also-- [Tutorial: Gathering threat intelligence and infrastructure chaining](gathering-threat-intelligence-and-infrastructure-chaining.md) 