Event banner
Microsoft Defender Threat Intelligence and Sentinel integration deep dive
Event Ended
Thursday, Apr 13, 2023, 07:30 AM PDTEvent details
See how quick detection and response are vital to navigating today's fast-moving cyberattacks. We'll break down a cyberattack and show how Microsoft Defender Threat Intelligence, combined with Micros...
Trevor_Rusher
Updated Dec 27, 2024
Apr 13, 2023
Is there a way to run the hunting queries against these TIs?
RijutaKapoor
Microsoft
Apr 13, 2023Yes we do provide some sample TI hunting queries that all start with "TI map" keyword. The TI Map hunting queries are all part of the "Threat Intelligence" solution on the content hub. You can get these queries by installing the solution. The queries are completely customizable incase you need to run them against a particular data type.
The queries get all indicators from the ThreatIntelligenceIndicators table in log analytics and the MDTI indicators are part of the table when you enable the MDTI connector.