Skip to content

Commit 0a128c5

Browse files
update whats new for brevity
1 parent f575375 commit 0a128c5

File tree

1 file changed

+2
-16
lines changed

1 file changed

+2
-16
lines changed

articles/sentinel/whats-new.md

Lines changed: 2 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -29,29 +29,15 @@ Now bring the high fidelity indicators of compromise (IOC) generated by Microsof
2929

3030
### Microsoft Defender Threat Intelligence solution (Preview)
3131

32-
A collection of playbooks are available in the new Microsoft Defender Threat Intelligence *solution* to compliment the MDTI *data connector*. Utilize the playbooks to enrich entities (Domains, Hosts and IPs) associated with Microsoft Sentinel **Incidents**. The enrichment uses comprehensive Threat Intelligence (TI) data to add risk scoring, useful tags, analyst insights, and links to published TI articles. What makes the TI data so comprehensive and compelling? Along with traditional TI datasets of DNS, reverse DNS, WHOIS, SSL certificates and subdomains, the MDTI enrichment works with advanced TI datasets like trackers, web components, host pairs, and cookies.
32+
A collection of playbooks is available in the new Microsoft Defender Threat Intelligence *solution*. Utilize the playbooks to enrich entities (Domains, Hosts and IPs) associated with Microsoft Sentinel **Incidents**. The enrichment uses comprehensive Threat Intelligence (TI) data to add risk scoring, useful tags, analyst insights, and links to published TI articles. What makes the TI data so comprehensive and compelling? Along with traditional TI datasets of DNS, reverse DNS, WHOIS, SSL certificates and subdomains, the MDTI enrichment works with advanced TI datasets like trackers, web components, host pairs, and cookies.
3333

3434
Enabling this solution helps your security team achieve the following goals:
3535
- accelerate investigations
3636
- increase visibility
3737
- respond more effectively to threats
3838
- maximize impact of existing security incident response
3939

40-
The playbooks included in the solution at launch are:
41-
42-
1. MDTI Intel Reputation
43-
44-
This playbook uses the Microsoft Defender Threat Intelligence Reputation Data to automatically enrich incidents generated by Microsoft Sentinel. Reputation information helps analysts designate indicators as benign, suspicious, or malicious. Each reputation result resides within a comment in the incident. Detailed scoring information justifies why a given indicator rates as suspicious or malicious, and links to the MDTI portal are included for more information.
45-
46-
1. MDTI Data WebComponents
47-
48-
Use this playbook to enrich your incidents with MDTI WebComponents data hosted by the indicators found within the incident. These components allow a user to understand the makeup of a webpage or the technology and services driving a specific piece of infrastructure. Pivoting on unique components can find actors' infrastructure or other target sites compromised. Users can also determine if a website might be vulnerable to a specific attack or compromise based on the technologies that it's running.
49-
50-
1. MDTI Automated Triage
51-
52-
This playbook also uses Microsoft Defender Threat Intelligence Reputation data to automatically enrich incidents generated by Microsoft Sentinel. After indicators are scored, the incident's severity is updated. For "suspicious", the incident severity is marked as "medium". If any indicator is labeled as "malicious", the incident is tagged as "high" severity. Regardless of the reputation state, comments are added to the incident outlining the reputation details with links to further information if applicable.
53-
54-
Find out more information about this solution in the Content hub, or [here](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/azuresentinel.azure-sentinel-solution-microsoft-defender-threat-intelligence) in the global Azure Marketplace.
40+
Check out the Tech Community blog for more information about the three playbooks released at launch!
5541

5642
### Automatically update the SAP data connector agent (Preview)
5743

0 commit comments

Comments
 (0)