Skip to content

Commit 15fe15e

Browse files
add ingestion rules
1 parent 644d3cf commit 15fe15e

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

articles/sentinel/understand-threat-intelligence.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ The following table outlines the activities required to make the most of threat
4040
| Action | Description|
4141
|---|---|
4242
| **Store threat intelligence in Microsoft Sentinel's workspace** | <ul><li>Import threat intelligence into Microsoft Sentinel by enabling data connectors to various threat intelligence platforms and feeds.</li><li>Connect threat intelligence to Microsoft Sentinel by using the upload API to connect various TI platforms or custom applications.</li><li>Create threat intelligence with a streamlined management interface.</li>|
43-
| **Manage threat intelligence** | <ul><li>View imported threat intelligence using queries or advanced search.</li><li>Curate threat intelligence with relationships or tags</li><li>Visualize key information about your TI with workbooks.</li>|
43+
| **Manage threat intelligence** | <ul><li>View imported threat intelligence using queries or advanced search.</li><li>Curate threat intelligence with relationships, ingestion rules or tags</li><li>Visualize key information about your TI with workbooks.</li>|
4444
| **Use threat intelligence** | <ul><li>Detect threats and generate security alerts and incidents with built-in analytics rule templates based on your threat intelligence.</li><li>Hunt for threats using your threat intel to ask the right questions about the signals captured for your organization.</li>|
4545

4646
Threat intelligence also provides useful context within other Microsoft Sentinel experiences, such as notebooks. For more information, see [Get started with notebooks and MSTICPy](/azure/sentinel/notebook-get-started).
@@ -49,7 +49,7 @@ Threat intelligence also provides useful context within other Microsoft Sentinel
4949

5050
## Import and connect threat intelligence
5151

52-
Most threat intelligence is imported using data connectors or an API. Here are the solutions available for Microsoft Sentinel.
52+
Most threat intelligence is imported using data connectors or an API. Configure ingestion rules to reduce noise and ensure your intelligence feeds are optimized. Here are the solutions available for Microsoft Sentinel.
5353

5454
- **Microsoft Defender Threat Intelligence** data connector to ingest Microsoft's threat intelligence
5555
- **Threat Intelligence - TAXII** data connector for industry-standard STIX/TAXII feeds

0 commit comments

Comments
 (0)