Microsoft Defender for Cloud
Cloud and workloads

Threat intelligence report

In brief

The page updates its metadata, changes wording from mitigating a specific issue to mitigating similar threats, and adds an introduction to steps for accessing a threat intelligence report.

What Defender admins need to know

Administrators should use the revised guidance when reviewing incident-response and threat-intelligence documentation; no action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • Campaign Report: focuses on details of specific attack campaigns.
  • Threat Summary Report: covers all of the items in the previous two reports.

This type of information is useful during the incident response process. Such as when there's an ongoing investigation to understand the source of the attack, the attacker’s motivations, and what to do to mitigate this issuesimilar threats in the future.

How to access the threat intelligence report?

To access a threat intelligence report, perform the following steps:

  1. From Defender for Cloud's menu, open the Security alerts page.
  2. Select an alert.