You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-iot/organizations/how-to-work-with-threat-intelligence-packages.md
+24-18Lines changed: 24 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,10 +1,11 @@
1
1
---
2
2
title: Update threat intelligence data
3
3
description: The threat intelligence data package is provided with each new Defender for IoT version, or if needed between releases.
4
-
ms.date: 06/02/2022
4
+
ms.date: 11/16/2022
5
5
ms.topic: how-to
6
6
---
7
7
# Threat intelligence research and packages
8
+
8
9
## Overview
9
10
10
11
Security teams at Microsoft carry out proprietary ICS threat intelligence and vulnerability research. These teams include MSTIC (Microsoft Threat Intelligence Center), DART (Microsoft Detection and Response Team), DCU (Digital Crimes Unit), and Section 52 (IoT/OT/ICS domain experts that track ICS-specific zero-days, reverse-engineering malware, campaigns, and adversaries)
@@ -66,42 +67,47 @@ You can change the sensor threat intelligence update mode after initial onboardi
66
67
67
68
Packages can be downloaded the Azure portal and manually uploaded to individual sensors. If the on-premises management console manages your sensors, you can download threat intelligence packages to the management console and push them to multiple sensors simultaneously.
68
69
69
-
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/download-screen.png" alt-text="Download updates in the Azure portal.":::
70
+
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/download-screen.png" alt-text="Screenshot of how to download updates in the Azure portal." lightbox="media/how-to-work-with-threat-intelligence-packages/download-screen.png":::
70
71
71
72
This option is available for both *cloud connected* and *locally managed* sensors.
1.Go to the Microsoft Defender for IoT **Updates**page.
78
+
1.In Defender for IoT on the Azure portal, go to the **Get started** > **Updates**tab.
79
79
80
-
2. Download and save the **Threat Intelligence** package.
80
+
1. In the **Sensor threat intelligence update** box, select **Download file** to download the latest threat intelligence package.
81
81
82
-
3. Sign in to the sensor console.
82
+
1. Sign in to the sensor console, and then select **System settings** > **Threat intelligence**.
83
83
84
-
4. On the side menu, select **System Settings**.
84
+
1. In the **Threat intelligence** pane, select **Upload file**. For example:
85
85
86
-
5. Select **Threat Intelligence Data**, and then select **Update**.
86
+
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/update-threat-intelligence-single-sensor.png" alt-text="Screenshot of where you can upload Threat Intelligence package to a single sensor." lightbox="media/how-to-work-with-threat-intelligence-packages/update-threat-intelligence-single-sensor.png":::
87
87
88
-
6. Upload the new package.
88
+
1. Browse to and select the package you'd downloaded from the Azure portal and upload it to the sensor.
89
89
90
90
**To upload to multiple sensors simultaneously:**
91
91
92
-
1. Go to the Microsoft Defender for IoT **Updates** page.
92
+
1. In Defender for IoT on the Azure portal, go to the **Get started** > **Updates** tab.
93
+
94
+
1. In the **Sensor threat intelligence update** box, select **Download file** to download the latest threat intelligence package.
95
+
96
+
1. Sign in to the management console and select **System settings**.
97
+
98
+
1. In the **Sensor Engine Configuration** area, select the sensors that you want to receive the updated packages. For example:
93
99
94
-
2. Download and save the **Threat Intelligence** package.
100
+
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/update-threat-intelligence-multiple-sensors.png" alt-text="Screenshot of where you can select which sensors you want to make changes to." lightbox="media/how-to-work-with-threat-intelligence-packages/update-threat-intelligence-multiple-sensors.png":::
95
101
96
-
3. Sign in to the management console.
102
+
1. In the **Sensor Threat Intelligence Data** section, select the plus sign (**+**).
97
103
98
-
4. On the side menu, select **System Settings**.
104
+
1. In the **Upload File** dialog, select **BROWSE FILE...** to browse to and select the update package. For example:
99
105
100
-
5. In the **Sensor Engine Configuration** section, select the sensors that should receive the updated packages.
106
+
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/upload-threat-intelligence-to-management-console.png" alt-text="Screenshot of where you can upload a Threat Intelligence package to multiple sensors." lightbox="media/how-to-work-with-threat-intelligence-packages/upload-threat-intelligence-to-management-console.png":::
101
107
102
-
6. In the **Select Threat Intelligence Data** section, select the plus sign (**+**).
108
+
1. Select **CLOSE** and then **SAVE CHANGES** to push the threat intelligence update to all selected sensors.
103
109
104
-
7. Upload the package.
110
+
:::image type="content" source="media/how-to-work-with-threat-intelligence-packages/save-changes-management-console.png" alt-text="Screenshot of where you can save changes made to selected sensors on the management console." lightbox="media/how-to-work-with-threat-intelligence-packages/save-changes-management-console.png":::
105
111
106
112
## Review package update status on the sensor
107
113
@@ -121,7 +127,7 @@ Review the following information about threat intelligence packages for your clo
121
127
122
128
1. Review the **Threat Intelligence version** installed on each sensor. Version naming is based on the day the package was built by Defender for IoT.
123
129
124
-
1. Review the **Threat Intelligence mode** . *Automatic* indicates that newly available packages will be automatically installed on sensors as they're released by Defender for IoT.
130
+
1. Review the **Threat Intelligence mode** . *Automatic* indicates that newly available packages will be automatically installed on sensors as they're released by Defender for IoT.
125
131
126
132
*Manual* indicates that you can push newly available packages directly to sensors as needed.
127
133
@@ -132,7 +138,7 @@ Review the following information about threat intelligence packages for your clo
132
138
- Update Available
133
139
- Ok
134
140
135
-
If cloud connected threat intelligence updates fail, review connection information in the **Sensor status** and **Last connected UTC** columns in the **Sites and Sensors** page.
141
+
If cloud connected threat intelligence updates fail, review connection information in the **Sensor status** and **Last connected UTC** columns in the **Sites and Sensors** page.
0 commit comments