Skip to content

Commit 30cc8cf

Browse files
authored
Merge pull request #2556 from austinmccollum/austinmc-ti-whatsnew
add blurb for new TI article overview for USX
2 parents 23893c9 + f45059b commit 30cc8cf

File tree

2 files changed

+22
-1
lines changed

2 files changed

+22
-1
lines changed
20.2 KB
Loading

unified-secops-platform/whats-new.md

Lines changed: 22 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,13 +22,33 @@ This article lists recent features added into Microsoft's unified SecOps platfor
2222

2323
## January 2025
2424

25+
- [Unified threat intelligence](#unified-threat-intelligence)
2526
- [Manage SecOps work natively with case management (Preview)](#case-management-preview)
2627
- [Unified device timeline in Microsoft Defender portal (Preview)](#unified-device-timeline-in-microsoft-defender-portal-preview)
2728
- [SOC optimization updates for unified coverage management](#soc-optimization-updates-for-unified-coverage-management)
2829

30+
### Unified threat intelligence
31+
32+
Microsoft Sentinel-powered threat intelligence has moved in the Defender portal to **Intel management**, unifying threat intelligence features. In the Azure portal, the location remains unchanged.
33+
34+
:::image type="content" source="media/whats-new/intel-management-navigation.png" alt-text="Screenshot showing new menu placement for Microsoft Sentinel threat intelligence.":::
35+
36+
Along with the new location, the management interface streamlines the creation and curation of threat intel with these key features:
37+
38+
- Define relationships as you create new STIX objects.
39+
- Curate existing threat intelligence with the new relationship builder.
40+
- Create multiple objects quickly by copying common metadata from a new or existing TI object with the duplicate feature.
41+
- Use advanced search to sort and filter your threat intelligence objects without even writing a Log Analytics query.
42+
43+
For more information, see the following articles:
44+
45+
- [Uncover adversaries with threat intelligence in Microsoft's unified SecOps platform](threat-intelligence-overview.md)
46+
- [New STIX objects in Microsoft Sentinel](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/announcing-public-preview-new-stix-objects-in-microsoft-sentinel/4369164)
47+
- [Understand threat intelligence](/azure/sentinel/understand-threat-intelligence#create-and-manage-threat-intelligence)
48+
2949
### Case management (Preview)
3050

31-
Case management is the first installment of an end-to-end solution that provides seamless management of your security work. SecOps teams maintain security context, work more efficiently and respond faster to attacks when they manage case work without leaving the Defender portal. Here's the initial set of scenarios and features that CMSK supports.
51+
Case management is the first installment of an end-to-end solution that provides seamless management of your security work. SecOps teams maintain security context, work more efficiently and respond faster to attacks when they manage case work without leaving the Defender portal. Here's the initial set of scenarios and features that case management supports.
3252

3353
- Define your own case workflow with custom status values
3454
- Assign tasks to collaborators and configure due dates
@@ -38,6 +58,7 @@ Case management is the first installment of an end-to-end solution that provides
3858
This is just the start. Stay tuned for additional capabilities as we evolve this solution.
3959

4060
For more information, see the following articles:
61+
4162
- [Manage cases natively in Microsoft's unified security operations (SecOps) platform](cases-overview.md)
4263
- [Microsoft Sentinel blog - Improve SecOps collaboration with case management](https://techcommunity.microsoft.com/blog/MicrosoftSentinelBlog/improve-secops-collaboration-with-case-management/4369044)
4364

0 commit comments

Comments
 (0)