Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
Some information relates to prereleased product that may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
Threat intelligence in the Microsoft Defender portal brings together Microsoft threat research, threat intelligence from your organization, and security context from across Microsoft Defender. Use threat intelligence to understand emerging threats, investigate threat actors and their infrastructure, assess the impact of threats on your organization, and support threat hunting and incident response.
Threat intelligence with ISOC
For Integrated Security Operations Center (ISOC) customers, an ISOC workspace is required to use threat intelligence capabilities available in preview.
For ISOC eligibility requirements, see ISOC in Microsoft Defender.
This workspace requirement applies only to ISOC and doesn't describe requirements for threat intelligence capabilities outside the ISOC experience.
Threat intelligence experiences in the Defender portal
Threat intelligence is organized into two primary experiences: Overview and Intel explorer.
Overview page
Use Overview to review threats that are relevant to your organization.
Overview includes:
- Executive summary - Review a summary generated by the Threat Intelligence Briefing Agent.
- Latest threats - Review recently published and updated threats.
- High-impact threats - Identify threats with the greatest impact on your organization.
- Highest exposure threats - Identify threats to which your organization has the highest exposure.
- Threat articles - Browse Microsoft threat intelligence content, including attack patterns, threat actors, campaigns, tools, vulnerabilities, and reports.
You can also configure email notifications to stay informed about updated threat intelligence.
Intel explorer
Use Intel explorer to search, filter, and investigate threat intelligence from Microsoft and your organization's threat intelligence sources.
You can browse threat intelligence by the following types:
- Campaigns
- Indicators
- Attack patterns
- Identities
- Threat actors
- Tools
- Vulnerabilities
- Reports
Use keyword search and filters such as targeted industry, targeted geography, and source to narrow the results. You can also apply filters that are specific to the selected threat intelligence type.
Threat analytics reports are available directly in Intel explorer.
For more information, see Explore threat intelligence with Intel explorer.
Investigate threat intelligence in entity pages
Entity pages for IP addresses, domains, URLs, and files are enriched with Microsoft Threat Intelligence data through the Threat Intelligence Insights tab. These enrichments surface reputation data, attributed threat reports, sandbox analysis results, and infrastructure relationship data directly in the entity page.
For more information, see View threat intelligence in entity pages.
Threat analytics reports
Threat analytics reports provide research and analysis from Microsoft security researchers about emerging threats, threat actors and campaigns, attack techniques, vulnerabilities, malware, and other security threats.
Reports can also incorporate data from your environment to help you understand whether a threat is affecting your organization and whether applicable protections are in place.
For more information, see Threat analytics reports in Microsoft Defender.
Use Microsoft Copilot in Defender for threat intelligence
Microsoft Copilot in Microsoft Defender brings Microsoft Security Copilot capabilities into supported threat intelligence experiences in the Defender portal. Use Copilot to summarize threat intelligence, prioritize threats based on your organization's exposure, and learn more about threat actors, tools, vulnerabilities, and other threats.
For more information, see Use Microsoft Security Copilot for threat intelligence.
Use Project Perception for threat intelligence
If your organization has access to Project Perception, use the Threat Intelligence Agent to analyze threat intelligence and turn it into actionable insights for your environment. The agent can extract indicators and threat actor information, map techniques to MITRE ATT&CK, assess threat relevance to your organization, and generate KQL hunting queries.
For more information, see Threat Intelligence Agent.
Related content
- Explore threat intelligence with Intel explorer
- Transition to the new Threat intelligence experience
- Threat analytics reports in Microsoft Defender
- View threat intelligence in entity pages
- Use Microsoft Security Copilot for threat intelligence
Tip
Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender XDR Tech Community.