Microsoft Sentinel
Developer and API

Investigation graph

In brief

The article’s metadata was refreshed, and wording and link formatting were updated in the investigation graph and threat intelligence instructions.

What Defender admins need to know

No administrator action is indicated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security engineer, I want to add entities to threat intelligence during incident investigations so that my team can track and manage indicators of compromise effectively.

Investigation graph

The investigation graph is a visual, intuitive tool that presents connections and patterns and enables your analysts to ask the right questions and follow leads. Use itthe investigation graph to add entities to your threat intelligence indicator lists by making them available across your workspace.

  1. On the Microsoft Sentinel menu, select Incidents from the Threat management section.

  2. When all the fields are filled in to your satisfaction, select Apply. A message appears in the upper-right corner to confirm that your indicator was created.

  3. The entity is added as threat intelligence in your workspace. You can find it in the threat intelligence management interface. You can also query it by finding and viewing threat intelligence with queries.

Related content