threat hunting
33 TopicsIntroducing the MDTI Premium Data Connector for Sentinel
The MDTI and Unified Security Operations Platform teams are excited to introduce an MDTI Premium data connector available in the Unified Security Operations Platform and standalone Sentinel experiences. This connector enables customers to apply the powerful raw and finished threat intelligence in MDTI, including high-fidelity indicators of compromise (IoCs), across their security operations to detect and respond to the latest threats.Unleash the Power of Threat Intel: Introducing the MDTI GitHub
Are you looking to enhance your organization's security processes? The Microsoft Defender Threat Intelligence (MDTI) GitHub offers technical solutions for common scenarios, including advanced hunting queries, brand intelligence, and the latest threat trends. Learn how to access the repository and run custom scenarios to unleash the power of threat intelligence. Take advantage of this opportunity to strengthen your security posture and protect against potential threats.11KViews1like1CommentNew Threat Actor Intel Profiles Added to MDTI
The Microsoft Defender Threat Intelligence (Defender TI) team has recently launched twenty-six new threat actor Intel Profiles, and more than 50 additional articles customers can leverage immediately to take an intel-led approach to defend their organization from the latest threats.8.5KViews0likes2CommentsWhat’s New: MDTI Interoperability with Microsoft 365 Defender
Microsoft Defender Threat Intelligence (MDTI) helps streamline security analyst triage, incident response, threat hunting, and vulnerability management workflows, aggregating and enriching critical threat information in an easy-to-use interface. At Microsoft Secure, we announced new features, including that MDTI is now available to licensed customers within the Microsoft 365 Defender (M365 Defender) portal, placing its powerful threat intelligence side-by-side with the advanced XDR functionality of M365 Defender.13KViews6likes1CommentWhat's New: Intel Profiles Deliver Crucial Information, Context About Threats
Microsoft is thrilled to introduce Intel Profiles within Microsoft Defender Threat Intelligence. This feature offers a single, reliable source of information for security operations teams, providing continuous monitoring of global threats and their malicious tools.13KViews2likes0CommentsPerforming a Successful Proof of Concept (PoC)
To effectively determine the benefits of adopting Defender Threat Intelligence, you should perform a Proof of Concept (PoC). Before enabling Defender Threat Intelligence, you and your team should go through a planning process to determine a series of tasks that must be accomplished in this PoC.13KViews3likes1CommentUsing Reputation and Analyst Insights Features For Quick Indicator Assessments
Understanding if a host, domain, or IP address is good, bad, or otherwise, can be difficult during your security incident triage process. Microsoft Defender Threat Intelligence's reputation and analyst insight features make it easier to quickly make these assessments. Quicker triage = more time spent focusing on investigating the most severe cyber threats.Get to Know the Datasets and How to Use Them During Investigations
The internet can be confusing sometimes. Understanding its datasets doesn't have to be. Come learn how Microsoft Defender Threat Intelligence's datasets can help you uncover related indicators of compromise, which can help you react more readily to threats and build up stronger defenses.13KViews4likes1Comment