Use matching analytics in Microsoft Sentinel to detect threats
In brief
The article clarifies supported data sources and adds an explicit prerequisite to install a supported data connector and its corresponding Content hub solution before enabling the rule. It also updates terminology, examples, and a related link.
What Defender admins need to know
Install the required connector and Content hub solution before enabling the rule so it can generate alerts from connected data sources.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Use matching analytics in Microsoft Sentinel to detect threats
Take advantage ofUse Microsoft threat intelligence produced by Microsoft to generate high-fidelity alerts and incidents withincidents. Enable the Microsoft Defender Threat Intelligence Analytics rule. Thisrule, a built-in rule in Microsoft SentinelSentinel. This rule matches indicators with Common Event Format (CEF) logs, Windows DNS events withevents, syslog data, and more. It checks for domain and IPv4 threat indicators, syslog data, and more.indicators across these data sources.
Prerequisites
You must installInstall one or more of the supported data connectors to produce high-fidelity alerts and incidents. Aconnectors. You don't need a premium Microsoft Defender Threat Intelligence license isn't required. Installlicense. To connect your data sources, install the appropriateright solutions from the Content hub to connect these. The following data sources:sources are supported:
- Common Event Format (CEF) via Legacy Agent
- Windows DNS via Legacy Agent (Preview)
- Microsoft 365 (formerly, Office 365)
- Azure activity logs
- Windows DNS via AMA
ASIMAdvanced Security Information Model (ASIM) Network sessions
:::image type="content" source="media/use-matching-analytics-to-detect-threats/matching-analytics-template-ga.png" alt-text="A screenshot that shows the Microsoft Defender Threat Intelligence Analytics rule data source connections.":::
Matching analytics is configured when you enable the Microsoft Defender Threat Intelligence Analytics rule.
Under the Configuration section, select the Analytics menu.
Select the Rule templates tab.
:::image type="content" source="media/use-matching-analytics-to-detect-threats/configure-matching-analytics-rule.png" alt-text="Screenshot that shows the Microsoft Defender Threat Intelligence Analytics rule enabled on the Active rules tab." lightbox="media/use-matching-analytics-to-detect-threats/configure-matching-analytics-rule.png":::
Microsoft Defender Threat Intelligence Analytics matches your logs with domain, IP, and URL indicators in the following ways:
If the Microsoft Use the following steps to triage through the incidents generated by the Microsoft Defender Threat Intelligence Analytics rule:
Alerts are Observe the indicator information. When a match is found, the indicator is published to the Log Analytics :::image type="content" source="media/use-matching-analytics-to-detect-threats/mdti-article-link.png" alt-text="Screenshot that shows an incident with a link to the Microsoft Defender Threat Intelligence reference article.":::
For more information, see
DataReview supported data sources and indicatorsTriage an incident generated by matching analytics
's analytics Defender Threat Intelligence Analytics rule finds a match, any alerts generated are grouped into incidents.
:::image type="content" source="media/use-matching-analytics-to-detect-threats/matching-analytics.png" alt-text="Screenshot of incident generated by matching analytics with details pane.":::
ObserveCheck the severity assigned toof the alerts and the incident. DependingAlert severity ranges from Informational to High based on how the indicator is matched, an appropriate severity is assigned to an alert from Informational to High.matched. For example, if thean indicator is matched with firewall logs that allowed the traffic,traffic produces a high-severity alert is generated. If thealert. The same indicator was matched with firewall logs that blocked the traffic, the generated alert istraffic produces a low or medium.medium alert.
then grouped on a per-observable basis ofby the indicator.indicator they match. For example, all alerts generated in a 24-hour time period that match the contoso.com domain are grouped into a singleone incident. The incident with a severity assignedis based on the highest alert severity.
ThreatIntelligenceIndicators table, and it appears on the Threat Intelligence page. For any indicators published from this rule, the source is defined as Microsoft Threat Intelligence Analytics.
Get more context from Microsoft Defender Threat Intelligence
Along with high-fidelity alerts and incidents, someSome Microsoft Defender Threat Intelligence indicators also include a link to the correspondinga related Intel Explorer reference article for thatarticle. Use this link to get more details about the indicator.
Searching and pivoting with Intel ExplorerThreat analytics in Microsoft Defender XDR.
Related content
@@ -6,12 +6,12 @@ ms.author: guywild author: guywi-ms ms.reviewer: noak ms.topic: how-to-ms.date: 06/15/2026+ms.date: 07/02/2026 appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ms.collection: usx-security-ms.custom: sfi-image-nochange, msecd-doc-authoring-1014+ms.custom: sfi-image-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted @@ -21,11 +21,11 @@ ai-usage: ai-assisted # Use matching analytics in Microsoft Sentinel to detect threats -Take advantage of threat intelligence produced by Microsoft to generate high-fidelity alerts and incidents with the **Microsoft Defender Threat Intelligence Analytics** rule. This built-in rule in Microsoft Sentinel matches indicators with Common Event Format (CEF) logs, Windows DNS events with domain and IPv4 threat indicators, syslog data, and more.+Use Microsoft threat intelligence to generate high-fidelity alerts and incidents. Enable the **Microsoft Defender Threat Intelligence Analytics** rule, a built-in rule in Microsoft Sentinel. This rule matches indicators with Common Event Format (CEF) logs, Windows DNS events, syslog data, and more. It checks for domain and IPv4 threat indicators across these data sources. ## Prerequisites -You must install one or more of the supported data connectors to produce high-fidelity alerts and incidents. A premium Microsoft Defender Threat Intelligence license isn't required. Install the appropriate solutions from the **Content hub** to connect these data sources:+Install one or more supported data connectors. You don't need a premium Microsoft Defender Threat Intelligence license. To connect your data sources, install the right solutions from the **Content hub**. The following data sources are supported: - Common Event Format (CEF) via Legacy Agent - Windows DNS via Legacy Agent (Preview)@@ -33,7 +33,7 @@ You must install one or more of the supported data connectors to produce high-fi - Microsoft 365 (formerly, Office 365) - Azure activity logs - Windows DNS via AMA- - ASIM Network sessions+ - Advanced Security Information Model (ASIM) Network sessions :::image type="content" source="media/use-matching-analytics-to-detect-threats/matching-analytics-template-ga.png" alt-text="A screenshot that shows the Microsoft Defender Threat Intelligence Analytics rule data source connections."::: @@ -52,6 +52,9 @@ You must install one or more of the supported data connectors to produce high-fi Matching analytics is configured when you enable the **Microsoft Defender Threat Intelligence Analytics** rule. +> [!IMPORTANT]+> Before you enable this rule, install at least one supported data connector and its corresponding Content hub solution. See [Prerequisites](#prerequisites) for the full list of supported data sources.+ 1. Under the **Configuration** section, select the **Analytics** menu. 1. Select the **Rule templates** tab.@@ -66,7 +69,8 @@ Matching analytics is configured when you enable the **Microsoft Defender Threat :::image type="content" source="media/use-matching-analytics-to-detect-threats/configure-matching-analytics-rule.png" alt-text="Screenshot that shows the Microsoft Defender Threat Intelligence Analytics rule enabled on the Active rules tab." lightbox="media/use-matching-analytics-to-detect-threats/configure-matching-analytics-rule.png"::: -## Data sources and indicators+<a name="data-sources-and-indicators"></a>+## Review supported data sources and indicators Microsoft Defender Threat Intelligence Analytics matches your logs with domain, IP, and URL indicators in the following ways: @@ -80,7 +84,7 @@ Microsoft Defender Threat Intelligence Analytics matches your logs with domain, ## Triage an incident generated by matching analytics -If Microsoft's analytics finds a match, any alerts generated are grouped into incidents.+If the **Microsoft Defender Threat Intelligence Analytics** rule finds a match, any alerts generated are grouped into incidents. Use the following steps to triage through the incidents generated by the **Microsoft Defender Threat Intelligence Analytics** rule: @@ -94,9 +98,9 @@ Use the following steps to triage through the incidents generated by the **Micro :::image type="content" source="media/use-matching-analytics-to-detect-threats/matching-analytics.png" alt-text="Screenshot of incident generated by matching analytics with details pane."::: -1. Observe the severity assigned to the alerts and the incident. Depending on how the indicator is matched, an appropriate severity is assigned to an alert from `Informational` to `High`. For example, if the indicator is matched with firewall logs that allowed the traffic, a high-severity alert is generated. If the same indicator was matched with firewall logs that blocked the traffic, the generated alert is low or medium.+1. Check the severity of the alerts and the incident. Alert severity ranges from `Informational` to `High` based on how the indicator is matched. For example, an indicator matched with firewall logs that allowed traffic produces a high-severity alert. The same indicator matched with firewall logs that blocked traffic produces a low or medium alert. - Alerts are then grouped on a per-observable basis of the indicator. For example, all alerts generated in a 24-hour time period that match the `contoso.com` domain are grouped into a single incident with a severity assigned based on the highest alert severity.+ Alerts are grouped by the indicator they match. For example, all alerts in a 24-hour period that match the `contoso.com` domain are grouped into one incident. The incident severity is based on the highest alert severity. 1. Observe the indicator information. When a match is found, the indicator is published to the Log Analytics `ThreatIntelligenceIndicators` table, and it appears on the **Threat Intelligence** page. For any indicators published from this rule, the source is defined as `Microsoft Threat Intelligence Analytics`. @@ -110,11 +114,11 @@ Here's an example of searching for the indicators in the management interface. ## Get more context from Microsoft Defender Threat Intelligence -Along with high-fidelity alerts and incidents, some Microsoft Defender Threat Intelligence indicators include a link to the corresponding Intel Explorer reference article for that indicator.+Some Microsoft Defender Threat Intelligence indicators also include a link to a related Intel Explorer article. Use this link to get more details about the indicator. :::image type="content" source="media/use-matching-analytics-to-detect-threats/mdti-article-link.png" alt-text="Screenshot that shows an incident with a link to the Microsoft Defender Threat Intelligence reference article."::: -For more information, see [Searching and pivoting with Intel Explorer](/defender/threat-intelligence/searching-and-pivoting).+For more information, see [Threat analytics in Microsoft Defender XDR](/defender-xdr/threat-analytics). ## Related content 