Skip to content

Commit 4569cf3

Browse files
Merge pull request #1293 from MicrosoftDocs/main
Publish main to live 09/09/2024, 11:00 AM IST
2 parents 067e9ec + 570899b commit 4569cf3

18 files changed

+57
-27
lines changed

defender/threat-intelligence/TOC.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,9 @@
3131
href: using-projects.md
3232
- name: Using Microsoft Copilot in Defender for threat intelligence
3333
href: using-copilot-threat-intelligence-defender-xdr.md
34+
- name: Enabling data connector for Defender TI in Microsoft Sentinel (Preview)
35+
href: /azure/sentinel/connect-mdti-data-connector
36+
3437
- name: Tutorials
3538
items:
3639
- name: Gathering threat intelligence and infrastructure chaining

defender/threat-intelligence/analyst-insights.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@ ms.custom: template-overview
1212

1313
# Analyst insights
1414

15-
>[!IMPORTANT]
16-
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) will be retired and will no longer be accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
15+
>[!IMPORTANT]
16+
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) was retired and is no longer accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
1717
1818
In Microsoft Defender Threat Intelligence (Defender TI), the **Analyst insights** section provides you with quick insights about an artifact that might help determine your next step in an investigation. This section lists any insights that apply to the artifact, and insights that don't apply for extra visibility.
1919

defender/threat-intelligence/data-sets.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@ ms.custom: template-concept
1212

1313
# Data sets
1414

15-
> [!IMPORTANT]
16-
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal <https://ti.defender.microsoft.com> will be retired and will no longer be accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
15+
>[!IMPORTANT]
16+
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) was retired and is no longer accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
1717
1818
Microsoft centralizes numerous data sets into Microsoft Defender Threat Intelligence (Defender TI), making it easier for Microsoft's customers and community to conduct infrastructure analysis. Microsoft's primary focus is to provide as much data as possible about internet infrastructure to support various security use cases.
1919

defender/threat-intelligence/gathering-threat-intelligence-and-infrastructure-chaining.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,8 @@ ms.custom: template-tutorial
1313

1414
# Tutorial: Gathering threat intelligence and infrastructure chaining
1515

16-
>[!IMPORTANT]
17-
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) will be retired and will no longer be accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
16+
>[!IMPORTANT]
17+
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) was retired and is no longer accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
1818
1919

2020
This tutorial walks you through how to perform several types of indicator searches and gather threat and adversary intelligence using Microsoft Defender Threat Intelligence (Defender TI) in the Microsoft Defender portal.

defender/threat-intelligence/gathering-vulnerability-intelligence.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,8 @@ ms.custom: template-tutorial
1212

1313
# Tutorial: Gathering vulnerability intelligence
1414

15-
>[!IMPORTANT]
16-
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) will be retired and will no longer be accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
15+
>[!IMPORTANT]
16+
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) was retired and is no longer accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
1717
1818

1919
This tutorial walks you through how to perform several types of indicator searches to gather vulnerability intelligence using Microsoft Defender Threat Intelligence (Defender TI) in the Microsoft Defender portal.

defender/threat-intelligence/infrastructure-chaining.md

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,9 @@ ms.custom: template-concept
1111
---
1212

1313
# Infrastructure chaining
14-
>[!IMPORTANT]
15-
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) will be retired and will no longer be accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
14+
15+
>[!IMPORTANT]
16+
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) was retired and is no longer accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
1617
1718
Infrastructure chaining uses the relationships between highly connected datasets to build out an investigation. This process is the core of threat infrastructure analysis and allows organizations to surface new connections, group similar attack activity and substantiate assumptions during incident response.
1819

defender/threat-intelligence/learn-how-to-access-microsoft-defender-threat-intelligence-and-make-customizations-in-your-portal.md

Lines changed: 24 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
---
22
title: 'Quickstart: Accessing Microsoft Defender Threat Intelligence (Defender TI)'
3-
description: In this quickstart, learn how to access Microsoft Defender Threat Intelligence (Defender TI) in the Microsoft Defender portal, as well as configure your profile and preferences and access help resources in the Defender portal.
3+
description: Learn how to access Microsoft Defender Threat Intelligence (Defender TI) in the Microsoft Defender portal, configure your profile and preferences, and access help resources.
44
author: alexroland24
55
ms.author: aroland
66
manager: dolmont
@@ -14,11 +14,11 @@ ms.collection: essentials-get-started
1414
# Quickstart: Learn how to access Microsoft Defender Threat Intelligence and make customizations
1515

1616
>[!IMPORTANT]
17-
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) will be retired and will no longer be accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
17+
> On June 30, 2024, The Microsoft Defender Threat Intelligence (Defender TI) standalone portal (https://ti.defender.microsoft.com) was retired and is no longer accessible. Customers can continue using Defender TI in the [Microsoft Defender portal](https://aka.ms/mdti-intel-explorer) or with [Microsoft Copilot for Security](security-copilot-and-defender-threat-intelligence.md). [Learn more](https://aka.ms/mdti-standaloneportal)
1818
1919
This guide walks you through how to access Microsoft Threat Intelligence (Defender TI) from the Microsoft Defender portal, adjust the portal's theme to make it easier on your eyes when using it, and find sources for enrichment so you can see more results when gathering threat intelligence.
2020

21-
:::image type="content" source="/defender/threat-intelligence/media/quickstart-intel-explorer.png" alt-text="Screenshot of the Microsoft Defender Threat Intelligence Intel explorer in the Microsoft Defender portal." lightbox="/defender/threat-intelligence/media/quickstart-intel-explorer.png":::
21+
:::image type="content" source="/defender/threat-intelligence/media/quickstart-intel-explorer.png" alt-text="Screenshot of the Microsoft Defender Threat Intelligence Intel explorer in the Microsoft Defender portal." lightbox="/defender/threat-intelligence/media/quickstart-intel-explorer.png":::
2222

2323
## Prerequisites
2424

@@ -37,6 +37,7 @@ This guide walks you through how to access Microsoft Threat Intelligence (Defend
3737
- Intel projects
3838

3939
:::image type="content" source="/defender/threat-intelligence/media/quickstart-navigation.png" alt-text="Screenshot of the Microsoft Defender portal with the Threat intelligence navigation links highlighted." lightbox="/defender/threat-intelligence/media/quickstart-navigation.png":::
40+
4041
## Adjust the Defender portal's display theme to dark or light mode
4142

4243
By default, the Defender portal's display theme is set to light mode. To switch to dark mode, on the Defender portal, navigate to **Home** then select **Dark mode** on the upper right-right corner of the home page.
@@ -47,6 +48,26 @@ To switch back to light mode, select **Light mode** in the same upper-right hand
4748

4849
![Partial screenshot of the Defender portal home page with the Light mode icon hightlighted.](media/quickstart-light-mode.png)
4950

51+
## Catch up on the latest threat intelligence
52+
53+
You can keep yourself updated with the latest and most notable threat intelligence articles through the **Featured threat intelligence article** widget or through the article digest notifications.
54+
55+
### Featured threat intelligence articles widget
56+
57+
The **Featured threat intelligence articles** widget in the Defender portal home page displays the recent Defender TI publications that are tagged as [Featured articles](what-is-microsoft-defender-threat-intelligence-defender-ti.md#featured-articles):
58+
59+
:::image type="content" source="/defender/threat-intelligence/media/mdti-featured-articles-widget.png" alt-text="Screenshot of Featured threat intelligence articles widget in the Defender portal home page." lightbox="/defender/threat-intelligence/media/mdti-featured-articles-widget.png":::
60+
61+
### Article digest
62+
63+
In the **Intel explorer** page, a banner message notifies you of the number of new Defender TI articles that were published since you last accessed the Defender portal. Select **Show me** to open a flyout panel that lists the articles you might have missed, then select any of the listed articles to open it:
64+
65+
:::image type="content" source="/defender/threat-intelligence/media/mdti-article-digest-01.png" alt-text="Screenshot of the Intel explorer article digest banner message notification and flyout panel." lightbox="/defender/threat-intelligence/media/mdti-article-digest-01.png":::
66+
67+
Select the **Clear** button in the flyout panel or close the banner message to clear the article digest:
68+
69+
70+
:::image type="content" source="/defender/threat-intelligence/media/mdti-article-digest-02.png" alt-text="Screenshot of the Intel explorer article digest flyout panel with the Clear button highlighted." lightbox="/defender/threat-intelligence/media/mdti-article-digest-02.png":::
5071

5172
## Get help and learn about Defender TI support resources
5273

716 KB
Loading
714 KB
Loading
441 KB
Loading

0 commit comments

Comments
 (0)