Skip to content

Commit b60ba37

Browse files
authored
Merge pull request #218370 from Shereen-Bhar/reminder-save-to-changes-when-uploading-a-TI
update uploading TI instructions
2 parents 59671d5 + 322e19a commit b60ba37

File tree

6 files changed

+24
-18
lines changed

6 files changed

+24
-18
lines changed

articles/defender-for-iot/organizations/how-to-work-with-threat-intelligence-packages.md

Lines changed: 24 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,11 @@
11
---
22
title: Update threat intelligence data
33
description: The threat intelligence data package is provided with each new Defender for IoT version, or if needed between releases.
4-
ms.date: 06/02/2022
4+
ms.date: 11/16/2022
55
ms.topic: how-to
66
---
77
# Threat intelligence research and packages
8+
89
## Overview
910

1011
Security teams at Microsoft carry out proprietary ICS threat intelligence and vulnerability research. These teams include MSTIC (Microsoft Threat Intelligence Center), DART (Microsoft Detection and Response Team), DCU (Digital Crimes Unit), and Section 52 (IoT/OT/ICS domain experts that track ICS-specific zero-days, reverse-engineering malware, campaigns, and adversaries)
@@ -66,42 +67,47 @@ You can change the sensor threat intelligence update mode after initial onboardi
6667

6768
Packages can be downloaded the Azure portal and manually uploaded to individual sensors. If the on-premises management console manages your sensors, you can download threat intelligence packages to the management console and push them to multiple sensors simultaneously.
6869

69-
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/download-screen.png" alt-text="Download updates in the Azure portal.":::
70+
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/download-screen.png" alt-text="Screenshot of how to download updates in the Azure portal." lightbox="media/how-to-work-with-threat-intelligence-packages/download-screen.png":::
7071

7172
This option is available for both *cloud connected* and *locally managed* sensors.
7273

7374
[!INCLUDE [root-of-trust](includes/root-of-trust.md)]
7475

75-
7676
**To upload to a single sensor:**
7777

78-
1. Go to the Microsoft Defender for IoT **Updates** page.
78+
1. In Defender for IoT on the Azure portal, go to the **Get started** > **Updates** tab.
7979

80-
2. Download and save the **Threat Intelligence** package.
80+
1. In the **Sensor threat intelligence update** box, select **Download file** to download the latest threat intelligence package.
8181

82-
3. Sign in to the sensor console.
82+
1. Sign in to the sensor console, and then select **System settings** > **Threat intelligence**.
8383

84-
4. On the side menu, select **System Settings**.
84+
1. In the **Threat intelligence** pane, select **Upload file**. For example:
8585

86-
5. Select **Threat Intelligence Data**, and then select **Update**.
86+
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/update-threat-intelligence-single-sensor.png" alt-text="Screenshot of where you can upload Threat Intelligence package to a single sensor." lightbox="media/how-to-work-with-threat-intelligence-packages/update-threat-intelligence-single-sensor.png":::
8787

88-
6. Upload the new package.
88+
1. Browse to and select the package you'd downloaded from the Azure portal and upload it to the sensor.
8989

9090
**To upload to multiple sensors simultaneously:**
9191

92-
1. Go to the Microsoft Defender for IoT **Updates** page.
92+
1. In Defender for IoT on the Azure portal, go to the **Get started** > **Updates** tab.
93+
94+
1. In the **Sensor threat intelligence update** box, select **Download file** to download the latest threat intelligence package.
95+
96+
1. Sign in to the management console and select **System settings**.
97+
98+
1. In the **Sensor Engine Configuration** area, select the sensors that you want to receive the updated packages. For example:
9399

94-
2. Download and save the **Threat Intelligence** package.
100+
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/update-threat-intelligence-multiple-sensors.png" alt-text="Screenshot of where you can select which sensors you want to make changes to." lightbox="media/how-to-work-with-threat-intelligence-packages/update-threat-intelligence-multiple-sensors.png":::
95101

96-
3. Sign in to the management console.
102+
1. In the **Sensor Threat Intelligence Data** section, select the plus sign (**+**).
97103

98-
4. On the side menu, select **System Settings**.
104+
1. In the **Upload File** dialog, select **BROWSE FILE...** to browse to and select the update package. For example:
99105

100-
5. In the **Sensor Engine Configuration** section, select the sensors that should receive the updated packages.
106+
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/upload-threat-intelligence-to-management-console.png" alt-text="Screenshot of where you can upload a Threat Intelligence package to multiple sensors." lightbox="media/how-to-work-with-threat-intelligence-packages/upload-threat-intelligence-to-management-console.png":::
101107

102-
6. In the **Select Threat Intelligence Data** section, select the plus sign (**+**).
108+
1. Select **CLOSE** and then **SAVE CHANGES** to push the threat intelligence update to all selected sensors.
103109

104-
7. Upload the package.
110+
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/save-changes-management-console.png" alt-text="Screenshot of where you can save changes made to selected sensors on the management console." lightbox="media/how-to-work-with-threat-intelligence-packages/save-changes-management-console.png":::
105111

106112
## Review package update status on the sensor
107113

@@ -121,7 +127,7 @@ Review the following information about threat intelligence packages for your clo
121127

122128
1. Review the **Threat Intelligence version** installed on each sensor. Version naming is based on the day the package was built by Defender for IoT.
123129

124-
1. Review the **Threat Intelligence mode** . *Automatic* indicates that newly available packages will be automatically installed on sensors as they're released by Defender for IoT.
130+
1. Review the **Threat Intelligence mode** . *Automatic* indicates that newly available packages will be automatically installed on sensors as they're released by Defender for IoT.
125131

126132
*Manual* indicates that you can push newly available packages directly to sensors as needed.
127133

@@ -132,7 +138,7 @@ Review the following information about threat intelligence packages for your clo
132138
- Update Available
133139
- Ok
134140

135-
If cloud connected threat intelligence updates fail, review connection information in the **Sensor status** and **Last connected UTC** columns in the **Sites and Sensors** page.
141+
If cloud connected threat intelligence updates fail, review connection information in the **Sensor status** and **Last connected UTC** columns in the **Sites and Sensors** page.
136142

137143
## Next steps
138144

71.7 KB
Loading
Loading
Loading
Loading
Loading

0 commit comments

Comments
 (0)