Skip to content

Commit 25f67b4

Browse files
update relationship use cases
1 parent 24376ae commit 25f67b4

File tree

1 file changed

+5
-3
lines changed

1 file changed

+5
-3
lines changed

articles/sentinel/understand-threat-intelligence.md

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -153,9 +153,11 @@ Establish connections between objects to enhance threat detection and response.
153153

154154
| Use case | Description |
155155
|---|---|
156-
| Connecting Threat Actor to Attack Pattern | The threat actor "APT29" uses the attack pattern "Phishing via Email" to gain initial access.|
157-
| Linking Indicator to Threat Actor| An indicator (malicious domain) is attributed to the threat actor "APT29". |
158-
| Associating Identity (Victim) with Attack Pattern| The organization "Example Corp" is targeted by the attack pattern "Phishing via Email".|
156+
| Connecting Threat Actor to Attack Pattern | The threat actor *APT29 uses* the attack pattern *Phishing via Email* to gain initial access.|
157+
| Linking Indicator to Threat Actor| An indicator *allyourbase.contoso.com* domain is attributed to the threat actor *APT29*. |
158+
| Associating Identity (Victim) with Attack Pattern| The *FourthCoffee* organization is targeted by the attack pattern *Phishing via Email*.|
159+
160+
The following image combines all of those connections with the relationship builder.
159161

160162
:::image type="content" source="media/understand-threat-intelligence/relationship-example.png" alt-text="Screenshot showing example relationship being built.":::
161163

0 commit comments

Comments
 (0)