Microsoft Sentinel
Cloud and workloads

Use Threat Indicators in Analytics Rules

In brief

The article’s wording, example description, metadata, and related threat-intelligence links were updated for clarity and consistency.

What Defender admins need to know

Administrators can use the revised guidance and links when configuring TI map analytics rules. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Use threat indicatorsThreat Indicators in analytics rulesAnalytics Rules titleSuffix: Microsoft Sentinel description: This article explains how to generate alerts and incidents with threat intelligence indicators in Microsoft Sentinel. ms.author: guywild author: guywi-ms ms.reviewer: yoninave ms.topic: how-to ms.date: 06/15/07/02/2026 appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ms.collection: usx-security ms.custom: sfi-image-nochange, msecd-doc-authoring-10141016 ai-usage: ai-assisted

Use threat indicators in analytics rules

After importing threat intelligence indicators into Microsoft Sentinel, youYou can use TI map analytics rules in Microsoft Sentinel to automaticallydetect threats. These rules match your imported threat indicators against events from connected data sources. When a match is found, the rules generate alerts and incidents whenfor your threat indicators match events from connected data sources.team to review.

Prerequisites

  • Threat indicators. These indicators can be from threat intelligence feeds, threat intelligence platforms, bulk import from a flat file, or manual input.
  • Data sources. Events from your data connectors must be flowing to your Microsoft Sentinel workspace.
  • An analytics rule of the format TI map.... ItThe analytics rule must use this format so that it can map theyour threat indicators you have withto the events you ingested.

Configure a rule to generate security alerts

The following example shows how to enable and configure a rule to generatethat generates security alerts by using thefrom your imported threat indicators that you imported into Microsoft Sentinel. For this example, useindicators. This example uses the rule template called TI map IP entity to AzureActivity. This rule matches any IP address-typeaddress threat indicator with all your Azure Activity events. When a match is found, it generates an alert is generated along withand a correspondingrelated incident for investigation by your security operations team.team to investigate.

This particular analytics rule requires the Azure Activity data connector (to import your Azure subscription-level events). It also requires one or both of the Threat Intelligence data connectors (to import threat indicators). The TI map IP entity to AzureActivity rule also triggers from imported indicators or manually created ones.

Related content

In this article, you learned how to use threat intelligence indicators to detect threats. For more about threat intelligence in Microsoft Sentinel, see the following articles: