Skip to content

Commit 8cdcdd8

Browse files
Merge pull request #5017 from MicrosoftDocs/main
[AutoPublish] main to live - 09/12 01:33 PDT | 09/12 14:03 IST
2 parents f3bec9e + a3fd2bb commit 8cdcdd8

14 files changed

+50
-14
lines changed

defender/threat-intelligence/analyst-insights.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: aroland
66
manager: dolmont
77
ms.service: threat-intelligence
88
ms.topic: overview
9-
ms.date: 01/15/2025
9+
ms.date: 09/12/2025
1010
ms.custom:
1111
- template-overview
1212
- cx-ti
@@ -15,6 +15,9 @@ ms.custom:
1515

1616
# Analyst insights
1717

18+
> [!IMPORTANT]
19+
> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)
20+
1821
In Microsoft Defender Threat Intelligence (Defender TI), the **Analyst insights** section provides you with quick insights about an artifact that might help determine your next step in an investigation. This section lists any insights that apply to the artifact, and insights that don't apply for extra visibility.
1922

2023
In the following example, you can quickly determine that the IP address is routable, hosts a web server, and had an open port within the past five days. Furthermore, the system displays rules that weren't triggered, which can be equally helpful when kick starting an investigation.

defender/threat-intelligence/data-sets.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: aroland
66
manager: dolmont
77
ms.service: threat-intelligence
88
ms.topic: concept-article
9-
ms.date: 01/15/2025
9+
ms.date: 09/12/2025
1010
ms.custom:
1111
- template-concept
1212
- cx-ti
@@ -15,6 +15,9 @@ ms.custom:
1515

1616
# Data sets
1717

18+
> [!IMPORTANT]
19+
> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)
20+
1821
Microsoft centralizes numerous data sets into Microsoft Defender Threat Intelligence (Defender TI), making it easier for Microsoft's customers and community to conduct infrastructure analysis. Microsoft's primary focus is to provide as much data as possible about internet infrastructure to support various security use cases.
1922

2023
Microsoft collects, analyzes, and indexes internet data to help you:

defender/threat-intelligence/gathering-threat-intelligence-and-infrastructure-chaining.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: aroland
66
manager: dolmont
77
ms.service: threat-intelligence
88
ms.topic: tutorial
9-
ms.date: 01/15/2025
9+
ms.date: 09/12/2025
1010
ms.custom:
1111
- template-overview
1212
- cx-ti
@@ -16,6 +16,9 @@ ms.custom:
1616

1717
# Tutorial: Gathering threat intelligence and infrastructure chaining
1818

19+
> [!IMPORTANT]
20+
> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)
21+
1922
This tutorial walks you through how to perform several types of indicator searches and gather threat and adversary intelligence using Microsoft Defender Threat Intelligence (Defender TI) in the Microsoft Defender portal.
2023

2124
## Prerequisites

defender/threat-intelligence/gathering-vulnerability-intelligence.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: aroland
66
manager: dolmont
77
ms.service: threat-intelligence
88
ms.topic: tutorial
9-
ms.date: 01/15/2025
9+
ms.date: 09/12/2025
1010
ms.custom:
1111
- template-overview
1212
- cx-ti
@@ -15,6 +15,9 @@ ms.custom:
1515

1616
# Tutorial: Gathering vulnerability intelligence
1717

18+
> [!IMPORTANT]
19+
> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)
20+
1821
This tutorial walks you through how to perform several types of indicator searches to gather vulnerability intelligence using Microsoft Defender Threat Intelligence (Defender TI) in the Microsoft Defender portal.
1922

2023
## Prerequisites

defender/threat-intelligence/infrastructure-chaining.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: aroland
66
manager: dolmont
77
ms.service: threat-intelligence
88
ms.topic: concept-article
9-
ms.date: 01/15/2025
9+
ms.date: 09/12/2025
1010
ms.custom:
1111
- template-overview
1212
- cx-ti
@@ -15,6 +15,9 @@ ms.custom:
1515

1616
# Infrastructure chaining
1717

18+
> [!IMPORTANT]
19+
> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)
20+
1821
Infrastructure chaining uses the relationships between highly connected datasets to build out an investigation. This process is the core of threat infrastructure analysis and allows organizations to surface new connections, group similar attack activity and substantiate assumptions during incident response.
1922

2023
![Infrastructure chaining](media/infrastructureChaining.png)

defender/threat-intelligence/learn-how-to-access-microsoft-defender-threat-intelligence-and-make-customizations-in-your-portal.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: aroland
66
manager: dolmont
77
ms.service: threat-intelligence
88
ms.topic: quickstart
9-
ms.date: 05/16/2025
9+
ms.date: 09/12/2025
1010
ms.custom:
1111
- template-overview
1212
- cx-ti
@@ -16,6 +16,9 @@ ms.collection: essentials-get-started
1616

1717
# Quickstart: Learn how to access Microsoft Defender Threat Intelligence and make customizations
1818

19+
> [!IMPORTANT]
20+
> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)
21+
1922
This guide walks you through how to access Microsoft Threat Intelligence (Defender TI) from the Microsoft Defender portal, adjust the portal's theme to make it easier on your eyes when using it, and find sources for enrichment so you can see more results when gathering threat intelligence.
2023

2124
:::image type="content" source="/defender/threat-intelligence/media/quickstart-intel-explorer.png" alt-text="Screenshot of the Microsoft Defender Threat Intelligence Intel explorer in the Microsoft Defender portal." lightbox="/defender/threat-intelligence/media/quickstart-intel-explorer.png":::

defender/threat-intelligence/reputation-scoring.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: aroland
66
manager: dolmont
77
ms.service: threat-intelligence
88
ms.topic: overview
9-
ms.date: 01/15/2025
9+
ms.date: 09/12/2025
1010
ms.custom:
1111
- template-overview
1212
- cx-ti
@@ -15,6 +15,9 @@ ms.custom:
1515

1616
# Reputation scoring
1717

18+
> [!IMPORTANT]
19+
> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)
20+
1821
Microsoft Defender Threat Intelligence (Defender TI) provides proprietary reputation scores for any host, domain, or IP address. Whether validating the reputation of a known or unknown entity, this score helps you quickly understand any detected ties to malicious or suspicious infrastructure. Defender TI provides quick information about the activity of these entities (for example, first- and last-seen timestamps, autonomous system numbers, and associated infrastructure) and a list of rules that affect the reputation score when applicable.
1922

2023
Reputation data is important to understanding the trustworthiness of your own attack surface and is also useful when assessing unknown hosts, domains, or IP addresses that appear in investigations. These scores uncover any prior malicious or suspicious activity that affected the entity, or other known indicators of compromise (IOCs) that should be considered.

defender/threat-intelligence/searching-and-pivoting.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: aroland
66
manager: dolmont
77
ms.service: threat-intelligence
88
ms.topic: how-to
9-
ms.date: 01/15/2025
9+
ms.date: 09/12/2025
1010
ms.custom:
1111
- template-overview
1212
- cx-ti
@@ -15,6 +15,9 @@ ms.custom:
1515

1616
# Searching and pivoting
1717

18+
> [!IMPORTANT]
19+
> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)
20+
1821
Microsoft Defender Threat Intelligence (Defender TI) offers a robust and flexible search engine to streamline the investigation process. Defender TI is designed to let you pivot across various indicators from different data sources, making it easier than ever to discover relationships between disparate infrastructure.
1922

2023
This article helps you understand how to conduct a search and pivot across different data sets to discover relationships between different artifacts.

defender/threat-intelligence/security-copilot-and-defender-threat-intelligence.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ ms.custom:
1616
- cx-ti
1717
- cx-mdti
1818
ms.topic: article
19-
ms.date: 04/22/2025
19+
ms.date: 09/12/2025
2020
---
2121

2222
# Microsoft Security Copilot in Microsoft Defender Threat Intelligence

defender/threat-intelligence/sorting-filtering-and-downloading-data.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.author: aroland
66
manager: dolmont
77
ms.service: threat-intelligence
88
ms.topic: how-to
9-
ms.date: 01/15/2025
9+
ms.date: 09/12/2025
1010
ms.custom:
1111
- template-overview
1212
- cx-ti
@@ -15,6 +15,9 @@ ms.custom:
1515

1616
# Sorting, filtering, and downloading data
1717

18+
> [!IMPORTANT]
19+
> Microsoft Defender Threat Intelligence (Defender TI) will be discontinued and merged into Microsoft Defender for a powerful unified experience. Existing customers will continue to have full access to their current Defender TI experience until the product is retired on August 1, 2026. [Learn more](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/mdti-is-converging-into-microsoft-sentinel-and-defender-xdr/4427991)
20+
1821
Microsoft Defender Threat Intelligence (Defender TI) lets you access our vast collection of crawling data in an indexed and pivot table format. These data sets can be large, returning expansive amounts of historic and recent data. By letting you appropriately sort and filter the data, we help you surface the connections of interest easily.
1922

2023
In this how-to article, you learn how to sort and filter data for the following data sets:

0 commit comments

Comments
 (0)