Tutorial: Gather vulnerability intelligence in Microsoft Defender
In brief
Microsoft Defender documentation now includes a tutorial for using Intel explorer to search CVEs, IP addresses, and domains and review related threat intelligence.
What Defender admins need to know
Administrators can use the tutorial to investigate vulnerability-related indicators in the Defender portal; no action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
new file mode 100644
title: 'Tutorial: Gather vulnerability intelligence in Microsoft Defender' description: Practice gathering vulnerability intelligence using Microsoft Threat Intelligence in the Microsoft Defender portal. ms.service: defender-xdr ms.author: pauloliveria author: poliveria ms.localizationpriority: medium ms.collection: - m365-security - tier1 ms.custom: - cx-ti ms.topic: tutorial ms.date: 07/30/2026 ai-usage: ai-assisted appliesto: - Microsoft Defender XDR - Microsoft Sentinel in the Microsoft Defender portal
Tutorial: Gather vulnerability intelligence
[!INCLUDE Microsoft Defender XDR rebranding]
This tutorial walks you through how to perform several types of indicator searches to gather vulnerability intelligence using Microsoft Threat Intelligence in the Microsoft Defender portal.
Prerequisites
- Access to the Microsoft Defender portal. Learn more about the Defender portal
Disclaimer
Microsoft Threat Intelligence might include live, real-time observations and threat indicators, including malicious infrastructure and adversary-threat tooling. Any IP address and domain searches in the Defender portal are safe to search. Microsoft shares online resources (for example, IP addresses and domain names) that are considered real threats posing a clear and present danger. Use your best judgment and minimize unnecessary risk while interacting with malicious systems when performing this tutorial. Microsoft minimizes risks by defanging malicious IP addresses, hosts, and domains.
Before you begin
As the disclaimer states previously, suspicious and malicious indicators are defanged for your safety. Remove any brackets from IP addresses, domains, and hosts when searching. Don't search these indicators directly in your browser.
Open Intel explorer in the Microsoft Defender portal
- Access the Defender portal and complete the Microsoft authentication process. Learn more about the Defender portal
- Navigate to Threat intelligence > Intel explorer.
Learn about Intel explorer home page features
- Review the Intel explorer search bar options by selecting its drop-down menu.
- Scroll down and review the featured and recent articles in their respective sections.
Perform indicator searches and gather vulnerability intelligence
Search CVE-2020-1472 in the Intel explorer search bar, then select and review the associated Intel profile CVE-2020-1472 - Netlogon Elevation of Privilege vulnerability.
Select the profile's Related articles tab then select the article Graphican: Nylon Typhoon (NICKEL) Uses New Backdoor in Attacks Targeting Foreign Ministries.
Select this newly opened article's Public indicators. You should see the IP address 50.116.3[.]164 among the listed indicators.
Navigate back to the Intel explorer search bar and search 50.116.3[.]164.
Review the following results in the Summary tab:
- Reputation
- Articles
- Services
- Resolutions
- Certificates
You can also select and review the information in the corresponding tabs.
Select the Resolutions tab then select piwik.enpers[.]com.
Review this domain's resolutions, WHOIS, certificates, subdomains, trackers, components, cookies, DNS, and reverse DNS data sets.
Perform the respective artifact searches from the previous steps. You could reference and use the different search options in the Intel explorer search bar dropdown menu.
Clean up resources
There are no resources to clean up in this section.
Related content
@@ -0,0 +1,74 @@+---+title: 'Tutorial: Gather vulnerability intelligence in Microsoft Defender'+description: Practice gathering vulnerability intelligence using Microsoft Threat Intelligence in the Microsoft Defender portal.+ms.service: defender-xdr+ms.author: pauloliveria+author: poliveria+ms.localizationpriority: medium+ms.collection:+ - m365-security+ - tier1+ms.custom:+ - cx-ti+ms.topic: tutorial+ms.date: 07/30/2026+ai-usage: ai-assisted+appliesto:+ - Microsoft Defender XDR+ - Microsoft Sentinel in the Microsoft Defender portal+---++# Tutorial: Gather vulnerability intelligence++[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]++This tutorial walks you through how to perform several types of indicator searches to gather vulnerability intelligence using Microsoft Threat Intelligence in the Microsoft Defender portal.++## Prerequisites++- Access to the [Microsoft Defender portal](https://security.microsoft.com/). [Learn more about the Defender portal](/defender-xdr/microsoft-365-defender-portal)++## Disclaimer++Microsoft Threat Intelligence might include live, real-time observations and threat indicators, including malicious infrastructure and adversary-threat tooling. Any IP address and domain searches in the Defender portal are safe to search. Microsoft shares online resources (for example, IP addresses and domain names) that are considered real threats posing a clear and present danger. Use your best judgment and minimize unnecessary risk while interacting with malicious systems when performing this tutorial. Microsoft minimizes risks by defanging malicious IP addresses, hosts, and domains.++## Before you begin++As the disclaimer states previously, suspicious and malicious indicators are defanged for your safety. Remove any brackets from IP addresses, domains, and hosts when searching. Don't search these indicators directly in your browser.++## Open Intel explorer in the Microsoft Defender portal++1. Access the [Defender portal](https://security.microsoft.com/) and complete the Microsoft authentication process. [Learn more about the Defender portal](/defender-xdr/microsoft-365-defender-portal)+1. Navigate to **Threat intelligence** > **Intel explorer**.++## Learn about Intel explorer home page features++1. Review the Intel explorer search bar options by selecting its drop-down menu.+1. Scroll down and review the featured and recent articles in their respective sections.++## Perform indicator searches and gather vulnerability intelligence++1. Search *CVE-2020-1472* in the **Intel explorer** search bar, then select and review the associated Intel profile *CVE-2020-1472 - Netlogon Elevation of Privilege vulnerability*.+1. Select the profile's **Related articles** tab then select the article *Graphican: Nylon Typhoon (NICKEL) Uses New Backdoor in Attacks Targeting Foreign Ministries*.+1. Select this newly opened article's **Public indicators**. You should see the IP address 50.116.3[.]164 among the listed indicators.+1. Navigate back to the **Intel explorer** search bar and search *50.116.3[.]164*.+1. Review the following results in the **Summary** tab:+ - Reputation+ - Articles+ - Services+ - Resolutions+ - Certificates++ You can also select and review the information in the corresponding tabs.+1. Select the **Resolutions** tab then select *piwik.enpers[.]com*.+1. Review this domain's resolutions, WHOIS, certificates, subdomains, trackers, components, cookies, DNS, and reverse DNS data sets.+1. Perform the respective artifact searches from the previous steps. You could reference and use the different search options in the **Intel explorer** search bar dropdown menu.++## Clean up resources++There are no resources to clean up in this section.++## Related content++- [Tutorial: Gather threat intelligence and perform infrastructure chaining](gathering-threat-intelligence-and-infrastructure-chaining.md)+- [View threat intelligence in entity pages](entity-page-threat-intelligence.md) 