You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/understand-threat-intelligence.md
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,10 +1,10 @@
1
1
---
2
-
title: Understand threat intelligence
2
+
title: Threat intelligence
3
3
titleSuffix: Microsoft Sentinel
4
4
description: Understand threat intelligence and how it integrates with features in Microsoft Sentinel to analyze data, detect threats, and enrich alerts.
5
5
author: austinmccollum
6
6
ms.topic: concept-article
7
-
ms.date: 01/27/2025
7
+
ms.date: 02/27/2025
8
8
ms.author: austinmc
9
9
appliesto:
10
10
- Microsoft Sentinel in the Azure portal
@@ -14,7 +14,7 @@ ms.collection: usx-security
14
14
#Customer intent: As a security analyst, I want to integrate threat intelligence into Microsoft Sentinel so that I can detect, investigate, and respond to potential security threats effectively.
15
15
---
16
16
17
-
# Understand threat intelligence in Microsoft Sentinel
17
+
# Threat intelligence in Microsoft Sentinel
18
18
19
19
Microsoft Sentinel is a cloud-native security information and event management (SIEM) solution with the ability to ingest, curate, and manage threat intelligence from numerous sources.
Copy file name to clipboardExpand all lines: articles/sentinel/work-with-threat-indicators.md
+4-4Lines changed: 4 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -47,7 +47,7 @@ Use the management interface to create STIX objects and perform other common thr
47
47
- Define relationships as you create new STIX objects.
48
48
- Quickly create multiple objects by using the duplicate feature to copy the metadata from a new or existing TI object.
49
49
50
-
For more information on supported STIX objects, see [Understand threat intelligence](understand-threat-intelligence.md#create-and-manage-threat-intelligence).
50
+
For more information on supported STIX objects, see [Threat intelligence in Microsoft Sentinel](understand-threat-intelligence.md#create-and-manage-threat-intelligence).
51
51
52
52
### Create a new STIX object
53
53
@@ -90,7 +90,7 @@ Reduce noise from your TI feeds, extend the validity of high value indicators, a
90
90
91
91
:::image type="content" source="media/work-with-threat-indicators/new-ingestion-rule.png" alt-text="Screenshot showing new ingestion rule creation for extending valid until date.":::
92
92
93
-
For more information, see [Understand threat intelligence ingestion rules](understand-threat-intelligence.md#configure-ingestion-rules).
93
+
For more information, see [Threat intelligence ingestion rules](understand-threat-intelligence.md#configure-ingestion-rules).
94
94
95
95
### Curate threat intelligence with the relationship builder
96
96
@@ -133,7 +133,7 @@ In the following image, multiple sources were used to search by placing them in
133
133
134
134
:::image type="content" source="media/work-with-threat-indicators/advanced-search.png" alt-text="Screenshot shows an OR operator combined with multiple AND conditions to search threat intelligence." lightbox="media/work-with-threat-indicators/advanced-search.png":::
135
135
136
-
Microsoft Sentinel only displays the most current version of your threat intel in this view. For more information on how objects are updated, see [Understand threat intelligence](understand-threat-intelligence.md#threat-intelligence-life-cycle).
136
+
Microsoft Sentinel only displays the most current version of your threat intel in this view. For more information on how objects are updated, see [Threat intelligence life cycle](understand-threat-intelligence.md#threat-intelligence-life-cycle).
137
137
138
138
IP and domain name indicators are enriched with extra `GeoLocation` and `WhoIs` data so you can provide more context for any investigations where indicator is found.
139
139
@@ -240,7 +240,7 @@ There's also a rich resource for [Azure Monitor workbooks on GitHub](https://git
240
240
241
241
For more information, see the following articles:
242
242
243
-
- [Understand threat intelligence in Microsoft Sentinel](understand-threat-intelligence.md).
243
+
- [Threat intelligence in Microsoft Sentinel](understand-threat-intelligence.md).
244
244
- Connect Microsoft Sentinel to [STIX/TAXII threat intelligence feeds](./connect-threat-intelligence-taxii.md).
245
245
- See which [TIPs, TAXII feeds, and enrichments](threat-intelligence-integration.md) can be readily integrated with Microsoft Sentinel.
0 commit comments