Microsoft Sentinel
Cloud and workloads

Use matching analytics in Microsoft Sentinel to detect threats

In brief

The article clarifies supported data sources and adds an explicit prerequisite to install a supported data connector and its corresponding Content hub solution before enabling the rule. It also updates terminology, examples, and a related link.

What Defender admins need to know

Install the required connector and Content hub solution before enabling the rule so it can generate alerts from connected data sources.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use matching analytics in Microsoft Sentinel to detect threats

Take advantage ofUse Microsoft threat intelligence produced by Microsoft to generate high-fidelity alerts and incidents withincidents. Enable the Microsoft Defender Threat Intelligence Analytics rule. Thisrule, a built-in rule in Microsoft SentinelSentinel. This rule matches indicators with Common Event Format (CEF) logs, Windows DNS events withevents, syslog data, and more. It checks for domain and IPv4 threat indicators, syslog data, and more.indicators across these data sources.

Prerequisites

You must installInstall one or more of the supported data connectors to produce high-fidelity alerts and incidents. Aconnectors. You don't need a premium Microsoft Defender Threat Intelligence license isn't required. Installlicense. To connect your data sources, install the appropriateright solutions from the Content hub to connect these. The following data sources:sources are supported:

  • Common Event Format (CEF) via Legacy Agent
  • Windows DNS via Legacy Agent (Preview)
  • Microsoft 365 (formerly, Office 365)
  • Azure activity logs
  • Windows DNS via AMA
  • ASIMAdvanced Security Information Model (ASIM) Network sessions

:::image type="content" source="media/use-matching-analytics-to-detect-threats/matching-analytics-template-ga.png" alt-text="A screenshot that shows the Microsoft Defender Threat Intelligence Analytics rule data source connections.":::

Matching analytics is configured when you enable the Microsoft Defender Threat Intelligence Analytics rule.

  1. Under the Configuration section, select the Analytics menu.

  2. Select the Rule templates tab.

:::image type="content" source="media/use-matching-analytics-to-detect-threats/configure-matching-analytics-rule.png" alt-text="Screenshot that shows the Microsoft Defender Threat Intelligence Analytics rule enabled on the Active rules tab." lightbox="media/use-matching-analytics-to-detect-threats/configure-matching-analytics-rule.png":::

DataReview supported data sources and indicators

Microsoft Defender Threat Intelligence Analytics matches your logs with domain, IP, and URL indicators in the following ways:

Triage an incident generated by matching analytics

If the Microsoft's analytics Defender Threat Intelligence Analytics rule finds a match, any alerts generated are grouped into incidents.

Use the following steps to triage through the incidents generated by the Microsoft Defender Threat Intelligence Analytics rule:

:::image type="content" source="media/use-matching-analytics-to-detect-threats/matching-analytics.png" alt-text="Screenshot of incident generated by matching analytics with details pane.":::
  1. ObserveCheck the severity assigned toof the alerts and the incident. DependingAlert severity ranges from Informational to High based on how the indicator is matched, an appropriate severity is assigned to an alert from Informational to High.matched. For example, if thean indicator is matched with firewall logs that allowed the traffic,traffic produces a high-severity alert is generated. If thealert. The same indicator was matched with firewall logs that blocked the traffic, the generated alert istraffic produces a low or medium.medium alert.

    Alerts are then grouped on a per-observable basis ofby the indicator.indicator they match. For example, all alerts generated in a 24-hour time period that match the contoso.com domain are grouped into a singleone incident. The incident with a severity assignedis based on the highest alert severity.

  2. Observe the indicator information. When a match is found, the indicator is published to the Log Analytics ThreatIntelligenceIndicators table, and it appears on the Threat Intelligence page. For any indicators published from this rule, the source is defined as Microsoft Threat Intelligence Analytics.

Get more context from Microsoft Defender Threat Intelligence

Along with high-fidelity alerts and incidents, someSome Microsoft Defender Threat Intelligence indicators also include a link to the correspondinga related Intel Explorer reference article for thatarticle. Use this link to get more details about the indicator.

:::image type="content" source="media/use-matching-analytics-to-detect-threats/mdti-article-link.png" alt-text="Screenshot that shows an incident with a link to the Microsoft Defender Threat Intelligence reference article.":::

For more information, see Searching and pivoting with Intel ExplorerThreat analytics in Microsoft Defender XDR.

Related content