Microsoft Sentinel
Cloud and workloads

Work With Threat Indicators

In brief

The article updates terminology and examples for threat intelligence management and ingestion rules, and adds portal-specific steps for viewing queries against the ThreatIntelIndicators table in the Defender and Azure portals.

What Defender admins need to know

Administrators can follow the updated guidance when managing threat intelligence and viewing related queries.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Access the management interface

Access the threat intelligence management interface from either the Defender portal or the Azure portal. Even though the navigation path differs between portals, the creation and management tasks have the same steps once you get there.reach the management interface.

Access intel management in the Defender portal

:::image type="content" source="media/work-with-threat-indicators/threat-intel-add-new-indicator.png" alt-text="Screenshot that shows adding a new threat indicator." lightbox="media/work-with-threat-indicators/threat-intel-add-new-indicator.png":::
  1. Choose the Object type, then fill in the form on the New TI object page. Required fields are marked with a red asterisk (*).
  2. Consider designating a sensitivity value, or Traffic light protocol (TLP) rating to the TI object. For more information on what thesensitivity values and TLP ratings represent, see Curate threat intelligence.
  3. If you know how this object relates to another threat intelligence object, indicate that connection with the Relationship type and the Target reference.
  4. Select Add for an individual object, or Add and duplicate if you want to create more items with the same metadata. When you select Add and duplicate, the common metadata section of each STIX object is copied to the new object.

Optimize threat intelligence feeds with ingestion rules

Reduce noise from your TI feeds, extend the validity of high value indicators, and add meaningful tags to incoming objects. These tasks are just some of the use cases for ingestion rules. Here are the steps for extending the Valid until date on high value indicators.

  1. Select Ingestion rules to open a whole new page to view existing rules and construct new rule logic.

  2. Enter a descriptive name for your rule. The ingestion rules page has ample rule for the name, but it's the only text description available to differentiate your rules without editing them.

  3. Select the Object type. This use caseThe example of extending indicator validity is based on extending the Valid from property, which is only available for Indicator object types.

  4. Add condition for Source Equals and select your high value Source.

  5. Add condition for Confidence Greater than or equal and enter a Confidence score.

  6. Select the Action. Since we want tothe rule should modify this indicator,matching indicators, select Edit.

  7. Select the Add action for Valid until, Extend by, and select a time span in days.

  8. Consider adding a tag to indicate the high value placed on these indicators, like Extended. The modifiedobject's Modified date field isn't updated by ingestion rules.

  9. Select the Order you want the rule to run. Rules run from lowest order number to highest. Each rule evaluates every object ingested.

  10. If the rule is ready to be enabled, toggle Status to on.

  11. Select Add to create the ingestion rule. | Indicates | Indicator Indicates Attack pattern or Threat actor | | Impersonates | Threat actor Impersonates Identity |

  12. For example,As an example of a relationship-builder configuration, you can connect a threat actor to an attack pattern, indicator, and identity using the relationship builder in the Defender portal.

    :::image type="content" source="media/work-with-threat-indicators/relationship-example-defender-portal.png" alt-text="Screenshot showing the relationship builder." lightbox="media/work-with-threat-indicators/relationship-example-defender-portal.png":::

:::image type="content" source="media/work-with-threat-indicators/advanced-search.png" alt-text="Screenshot shows an OR operator combined with multiple AND conditions to search threat intelligence." lightbox="media/work-with-threat-indicators/advanced-search.png":::

Microsoft Sentinel only displays the most current version of your threat intel in this view.the management interface. For more information on how objects are updated, see Threat intelligence lifecycle.

IP and domain name indicators are enriched with extra GeoLocation and WhoIs data so you can provide more context for any investigations where the indicator is found.

  1. Select Add tags and tag them all at once with one or more tags.
  2. Because tagging is free-form, we recommend that you create standard naming conventions for tags in your organization.

Edit threat intelligence one object at a time, whether created directly in Microsoft Sentinel or from partner sources, like TIP and TAXII servers. For threat intel created in the management interface, all fields are editable. For threat intel ingested from partner sources, only specific fields are editable, including tags, Expiration date, Confidence, and Revoked. Either way,Whether the threat intel was created in Microsoft Sentinel or ingested from a partner source, only the latest version of the object appears in the management interface.

For more information on how threat intel is updated, see View your threat intelligence.

View your threat intelligence with queries, regardless of the source feed or method you used to ingest them.

Threat indicators are stored in the Microsoft Sentinel ThreatIntelIndicators table. ThisThe ThreatIntelIndicators table is the basis for threat intelligence queries performed by other Microsoft Sentinel features, such as Analytics, Hunting, and Workbooks.

Defender portal

To view threat intelligence queries in the Defender portal, complete the following steps.

  1. For Microsoft Sentinel in the Defender portal, select Investigation & response > Hunting > Advanced hunting.

  2. The ThreatIntelIndicators table is located under the Microsoft Sentinel group.

Azure portal

To view threat intelligence queries in the Azure portal, complete the following steps.

  1. For Microsoft Sentinel in the Azure portal, under General, select Logs.

  2. Select the Preview data icon (the eye) next to the table name. Select See in query editor to run a query that shows records from thisthe ThreatIntelIndicators table.

Your results should look similar to the sample ThreatIntelligenceIndicator table results with expanded details.

 :::image type="content" source="media/work-with-threat-indicators/threat-intel-verify-data.png" alt-text="Screenshot that shows verifying that you have data.":::
  1. Select Save, and choose an Azure location in which to store the workbook. This stepSaving the workbook is required if you intend to modify the workbook in any way and save your changes.

  2. Now select View saved workbook to open the workbook for viewing and editing.

Export threat intelligence

Microsoft Sentinel lets you export threat intelligence to other destinations. For example, if you've ingested threat intelligence using the Threat Intelligence - TAXII data connector, you can export threat intelligence back to the source platform for bi-directional intelligence sharing. The Microsoft Sentinel threat intelligence export feature reduces the need for manual processes or custom playbooks to distribute threat intelligence.

  1. In the Export pane, from the Export TI dropdown, select the server you want to export your threat intelligence to.

    If there isn't a server listed, you need to configure a TAXII 2.1 server for export first, as described in Enable the Threat intelligence - TAXII Export data connector. Microsoft Sentinel currently supports exporting to TAXII 2.1-based platforms only.

  2. Select Export.

To access the export history: