Microsoft Sentinel
Cloud and workloads

Threat Detection

In brief

The threat detection page now links to the updated Microsoft Defender Threat Intelligence page.

What Defender admins need to know

No administrator action is required; the updated link provides the current MDTI information.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Take advantage of threat intelligence produced by Microsoft to generate high fidelity alerts and incidents with the Microsoft Threat Intelligence Analytics rule. This unique rule isn't customizable, but when enabled, automatically matches Common Event Format (CEF) logs, Syslog data or Windows DNS events with domain, IP and URL threat indicators from Microsoft Threat Intelligence. Certain indicators contain more context information through MDTI (Microsoft Defender Threat Intelligence).

For more information on how to enable this rule, see Use matching analytics to detect threats.
For more information on MDTI, see What is Microsoft Defender Threat IntelligenceWhat is Microsoft Defender Threat Intelligence.

Advanced multistage attack detection (Fusion)