You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
-[Manage SecOps work natively with case management (Preview)](#case-management-preview)
26
27
-[Unified device timeline in Microsoft Defender portal (Preview)](#unified-device-timeline-in-microsoft-defender-portal-preview)
27
28
-[SOC optimization updates for unified coverage management](#soc-optimization-updates-for-unified-coverage-management)
28
29
30
+
### Unified threat intelligence
31
+
32
+
Microsoft Sentinel-powered threat intelligence has moved in the Defender portal to **Intel management**, unifying threat intelligence features. In the Azure portal, the location remains unchanged.
33
+
34
+
:::image type="content" source="media/whats-new/intel-management-navigation.png" alt-text="Screenshot showing new menu placement for Microsoft Sentinel threat intelligence.":::
35
+
36
+
Along with the new location, the management interface streamlines the creation and curation of threat intel with these key features:
37
+
38
+
- Define relationships as you create new STIX objects.
39
+
- Curate existing threat intelligence with the new relationship builder.
40
+
- Create multiple objects quickly by copying common metadata from a new or existing TI object with the duplicate feature.
41
+
- Use advanced search to sort and filter your threat intelligence objects without even writing a Log Analytics query.
42
+
43
+
For more information, see the following articles:
44
+
45
+
-[Uncover adversaries with threat intelligence in Microsoft's unified SecOps platform](threat-intelligence-overview.md)
46
+
-[New STIX objects in Microsoft Sentinel](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/announcing-public-preview-new-stix-objects-in-microsoft-sentinel/4369164)
Case management is the first installment of an end-to-end solution that provides seamless management of your security work. SecOps teams maintain security context, work more efficiently and respond faster to attacks when they manage case work without leaving the Defender portal. Here's the initial set of scenarios and features that CMSK supports.
51
+
Case management is the first installment of an end-to-end solution that provides seamless management of your security work. SecOps teams maintain security context, work more efficiently and respond faster to attacks when they manage case work without leaving the Defender portal. Here's the initial set of scenarios and features that case management supports.
32
52
33
53
- Define your own case workflow with custom status values
34
54
- Assign tasks to collaborators and configure due dates
@@ -38,6 +58,7 @@ Case management is the first installment of an end-to-end solution that provides
38
58
This is just the start. Stay tuned for additional capabilities as we evolve this solution.
39
59
40
60
For more information, see the following articles:
61
+
41
62
-[Manage cases natively in Microsoft's unified security operations (SecOps) platform](cases-overview.md)
42
63
-[Microsoft Sentinel blog - Improve SecOps collaboration with case management](https://techcommunity.microsoft.com/blog/MicrosoftSentinelBlog/improve-secops-collaboration-with-case-management/4369044)
0 commit comments