Use Threat Indicators in Analytics Rules
In brief
The article’s wording, example description, metadata, and related threat-intelligence links were updated for clarity and consistency.
What Defender admins need to know
Administrators can use the revised guidance and links when configuring TI map analytics rules. No action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
title: Use threat indicatorsThreat Indicators in analytics rulesAnalytics Rules
titleSuffix: Microsoft Sentinel
description: This article explains how to generate alerts and incidents with threat intelligence indicators in Microsoft Sentinel.
ms.author: guywild
author: guywi-ms
ms.reviewer: yoninave
ms.topic: how-to
ms.date: 06/15/07/02/2026
appliesto:
- Microsoft Sentinel in the Microsoft Defender portal
- Microsoft Sentinel in the Azure portal
ms.collection: usx-security
ms.custom: sfi-image-nochange, msecd-doc-authoring-10141016
ai-usage: ai-assisted
Use threat indicators in analytics rules
After importing threat intelligence indicators into Microsoft Sentinel, youYou can use TI map analytics rules in Microsoft Sentinel to automaticallydetect threats. These rules match your imported threat indicators against events from connected data sources. When a match is found, the rules generate alerts and incidents whenfor your threat indicators match events from connected data sources.team to review.
Prerequisites
- Threat indicators. These indicators can be from threat intelligence feeds, threat intelligence platforms, bulk import from a flat file, or manual input.
- Data sources. Events from your data connectors must be flowing to your Microsoft Sentinel workspace.
- An analytics rule of the format
TI map....ItThe analytics rule must use this format so that it can maptheyour threat indicatorsyou have withto the events you ingested.
Configure a rule to generate security alerts
The following example shows how to enable and configure a rule to generatethat generates security alerts by using thefrom your imported threat indicators that you imported into Microsoft Sentinel. For this example, useindicators. This example uses the rule template called TI map IP entity to AzureActivity. This rule matches any IP address-typeaddress threat indicator with all your Azure Activity events. When a match is found, it generates an alert is generated along withand a correspondingrelated incident for investigation by your security operations team.team to investigate.
This particular analytics rule requires the Azure Activity data connector (to import your Azure subscription-level events). It also requires one or both of the Threat Intelligence data connectors (to import threat indicators). The TI map IP entity to AzureActivity rule also triggers from imported indicators or manually created ones.
Related content
In this article, you learned how to use threat intelligence indicators to detect threats. For more about threat intelligence in Microsoft Sentinel, see the following articles:
- Work with threat indicators in Microsoft Sentinel
Connect Microsoft Sentinel to STIX/TAXII threat intelligence feeds.Use STIX/TAXII to import and export threat intelligence in Microsoft SentinelConnect threat intelligence platforms to Microsoft Sentinel.Connect your threat intelligence platform to Microsoft SentinelSee whichThreat intelligence integration in Microsoft Sentinelcan be readily integrated with Microsoft Sentinel.
@@ -1,17 +1,17 @@ ----title: Use threat indicators in analytics rules+title: Use Threat Indicators in Analytics Rules titleSuffix: Microsoft Sentinel description: This article explains how to generate alerts and incidents with threat intelligence indicators in Microsoft Sentinel. ms.author: guywild author: guywi-ms ms.reviewer: yoninave ms.topic: how-to-ms.date: 06/15/2026+ms.date: 07/02/2026 appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ms.collection: usx-security-ms.custom: sfi-image-nochange, msecd-doc-authoring-1014+ms.custom: sfi-image-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted @@ -21,17 +21,17 @@ ai-usage: ai-assisted # Use threat indicators in analytics rules -After importing threat intelligence indicators into Microsoft Sentinel, you can use TI map analytics rules to automatically generate alerts and incidents when your threat indicators match events from connected data sources.+You can use TI map analytics rules in Microsoft Sentinel to detect threats. These rules match your imported threat indicators against events from connected data sources. When a match is found, the rules generate alerts and incidents for your team to review. ## Prerequisites - Threat indicators. These indicators can be from threat intelligence feeds, threat intelligence platforms, bulk import from a flat file, or manual input. - Data sources. Events from your data connectors must be flowing to your Microsoft Sentinel workspace.-- An analytics rule of the format `TI map...`. It must use this format so that it can map the threat indicators you have with the events you ingested.+- An analytics rule of the format `TI map...`. The analytics rule must use this format so that it can map your threat indicators to the events you ingested. ## Configure a rule to generate security alerts -The following example shows how to enable and configure a rule to generate security alerts by using the threat indicators that you imported into Microsoft Sentinel. For this example, use the rule template called **TI map IP entity to AzureActivity**. This rule matches any IP address-type threat indicator with all your Azure Activity events. When a match is found, an alert is generated along with a corresponding incident for investigation by your security operations team.+The following example shows how to enable and configure a rule that generates security alerts from your imported threat indicators. This example uses the rule template called **TI map IP entity to AzureActivity**. This rule matches any IP address threat indicator with your Azure Activity events. When a match is found, it generates an alert and a related incident for your security operations team to investigate. This particular analytics rule requires the Azure Activity data connector (to import your Azure subscription-level events). It also requires one or both of the Threat Intelligence data connectors (to import threat indicators). The **TI map IP entity to AzureActivity** rule also triggers from imported indicators or manually created ones. @@ -84,9 +84,7 @@ In Microsoft Sentinel, the alerts generated from analytics rules also generate s ## Related content -In this article, you learned how to use threat intelligence indicators to detect threats. For more about threat intelligence in Microsoft Sentinel, see the following articles:- - [Work with threat indicators in Microsoft Sentinel](work-with-threat-indicators.md)-- Connect Microsoft Sentinel to [STIX/TAXII threat intelligence feeds](./connect-threat-intelligence-taxii.md).-- [Connect threat intelligence platforms](./connect-threat-intelligence-tip.md) to Microsoft Sentinel.-- See which [TIP platforms, TAXII feeds, and enrichments](threat-intelligence-integration.md) can be readily integrated with Microsoft Sentinel.+- [Use STIX/TAXII to import and export threat intelligence in Microsoft Sentinel](connect-threat-intelligence-taxii.md)+- [Connect your threat intelligence platform to Microsoft Sentinel](connect-threat-intelligence-tip.md)+- [Threat intelligence integration in Microsoft Sentinel](threat-intelligence-integration.md) 