Microsoft Sentinel
Cloud and workloads

Use STIX/TAXII to import and export threat intelligence in Microsoft Sentinel

In brief

The Microsoft Sentinel TAXII article was revised with clearer wording, reorganized setup steps, updated links, and refreshed metadata. It now explicitly documents importing from TAXII 2.0 or 2.1 and exporting with TAXII 2.1.

What Defender admins need to know

Administrators configuring TAXII integrations should follow the updated setup steps and version guidance. No required action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use STIX/TAXII to import and export threat intelligence in Microsoft Sentinel

STIX and TAXII are the most widely adopted industrycommon open standards for transmittingsharing threat intelligence. Microsoft Sentinel supports integration with threat intelligence platforms using the standards, and provideshas built-in connectors for importingthat use these standards to import and exportingexport threat intelligence.data.

Use the Threat Intelligence – TAXII data connector to importpull threat indicators from TAXII 2.0 or 2.1 servers into your Sentinel workspace.servers. To sharesend threat intelligence externally, configuredata to outside platforms, set up the Threat Intelligence – TAXII Export connector, which enables secure, standards-based export to supportedconnector for TAXII 2.1 platforms.export.

This article walksshows you throughhow to set up both processes - connecting to STIX/TAXII feeds for import and configuring export towith TAXII servers.

Learn more about threat intelligence in Microsoft Sentinel, and specifically about the TAXII feeds that you can integrate within Microsoft Sentinel.

[!INCLUDE reference-to-feature-availability]

Install the Threat Intelligence solution in Microsoft Sentinel

To import threat indicators into Microsoft Sentinel from a TAXII server or export threat indicators from Microsoft Sentinel,with a TAXII server, install the Threat Intelligence solution:

  1. For Microsoft Sentinel in the Azure portal, under Content management, select Content hub.

  2. Select the :::image type="icon" source="media/connect-mdti-data-connector/install-update-button.png"::: Install/Update button.

For more information about how toTo manage the solution components,parts, see Discover and deploy out-of-the-box content.

Enable the Threat Intelligence - TAXII data connector

:::image type="content" source="media/connect-threat-intelligence-taxii/taxii-data-connector.png" alt-text="Screenshot that shows the Data connectors page with the TAXII data connector listed." lightbox="media/connect-threat-intelligence-taxii/taxii-data-connector.png":::
  1. EnterIn the Friendly name text box, enter a name for this TAXII server collection in the Friendly name text box. collection.

  2. Fill in the text boxes for API root URL, Collection ID, Username (if necessary)needed), and Password (if necessary)needed).

  3. Choose the group of indicators and the polling frequency you want. frequency.

  4. Select Add.

    :::image type="content" source="media/connect-threat-intelligence-taxii/threat-intel-configure-taxii-servers.png" alt-text="Screenshot that shows configuring TAXII servers.":::

You should receive confirmation that a connection to the TAXII server was established successfully. Repeat the last step as many times as you want to connect to multiple collections from one or more TAXII servers.

Within a few minutes, threat indicators should begin flowing into thisyour Microsoft Sentinel workspace. Find the new indicators on the Threat intelligence pane. You can access itthe Threat intelligence pane from the Microsoft Sentinel menu.

IP allowlisting for the Microsoft Sentinel TAXII client

To configure the Threat Intelligence - TAXII Export connector:

  1. Make sureConfirm you have the latest version of the Threat Intelligence solution in Microsoft Sentinel.solution. For more information,details, see Install the Threat Intelligence solution in Microsoft Sentinel.

  2. Select the Data connectors menu.

  3. Select the Threat intelligence - TAXII Export data connector and thenconnector. Then select Open connector page in the side pane.

    :::image type="content" source="media/connect-threat-intelligence-taxii/taxii-export-data-connector.png" alt-text="Screenshot that shows the Data connectors page with the TAXII Export data connector listed." lightbox="media/connect-threat-intelligence-taxii/taxii-export-data-connector.png":::

  4. In the Configuration area on the Threat intelligence - TAXII Export page:

    • Enter a name for this TAXII server collection inIn the Friendly name (for server) text box.box, enter a name for this server.
    • Fill in the textboxes for API root URL, and Collection ID. For more information,details, see Get the TAXII server API root and collection ID.
    • Select anFrom the Authentication type dropdown, select Basic authentication or API key from the Authentication type dropdown and provide the relevant authentication details.. Then enter your credentials.
    • Select Enable rules to apply the rules described on the connector page rules to all exported threat intelligence.data.

    For example: