Edit

Threat intelligence in Microsoft Defender

Important

Some information relates to prereleased product that may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.

Threat intelligence in the Microsoft Defender portal brings together Microsoft threat research, threat intelligence from your organization, and security context from across Microsoft Defender. Use threat intelligence to understand emerging threats, investigate threat actors and their infrastructure, assess the impact of threats on your organization, and support threat hunting and incident response.

Threat intelligence with ISOC

For Integrated Security Operations Center (ISOC) customers, an ISOC workspace is required to use threat intelligence capabilities available in preview.

For ISOC eligibility requirements, see ISOC in Microsoft Defender.

This workspace requirement applies only to ISOC and doesn't describe requirements for threat intelligence capabilities outside the ISOC experience.

Threat intelligence experiences in the Defender portal

Threat intelligence is organized into two primary experiences: Overview and Intel explorer.

Overview page

Use Overview to review threats that are relevant to your organization.

Screenshot showing the threat intelligence overview with an executive summary, latest threats, and high-impact threats.

Overview includes:

  • Executive summary - Review a summary generated by the Threat Intelligence Briefing Agent.
  • Latest threats - Review recently published and updated threats.
  • High-impact threats - Identify threats with the greatest impact on your organization.
  • Highest exposure threats - Identify threats to which your organization has the highest exposure.
  • Threat articles - Browse Microsoft threat intelligence content, including attack patterns, threat actors, campaigns, tools, vulnerabilities, and reports.

You can also configure email notifications to stay informed about updated threat intelligence.

Intel explorer

Use Intel explorer to search, filter, and investigate threat intelligence from Microsoft and your organization's threat intelligence sources.

Screenshot showing Intel explorer with threat intelligence search, filters, categories, and results.

You can browse threat intelligence by the following types:

  • Campaigns
  • Indicators
  • Attack patterns
  • Identities
  • Threat actors
  • Tools
  • Vulnerabilities
  • Reports

Use keyword search and filters such as targeted industry, targeted geography, and source to narrow the results. You can also apply filters that are specific to the selected threat intelligence type.

Threat analytics reports are available directly in Intel explorer.

For more information, see Explore threat intelligence with Intel explorer.

Investigate threat intelligence in entity pages

Entity pages for IP addresses, domains, URLs, and files are enriched with Microsoft Threat Intelligence data through the Threat Intelligence Insights tab. These enrichments surface reputation data, attributed threat reports, sandbox analysis results, and infrastructure relationship data directly in the entity page.

For more information, see View threat intelligence in entity pages.

Threat analytics reports

Threat analytics reports provide research and analysis from Microsoft security researchers about emerging threats, threat actors and campaigns, attack techniques, vulnerabilities, malware, and other security threats.

Reports can also incorporate data from your environment to help you understand whether a threat is affecting your organization and whether applicable protections are in place.

For more information, see Threat analytics reports in Microsoft Defender.

Use Microsoft Copilot in Defender for threat intelligence

Microsoft Copilot in Microsoft Defender brings Microsoft Security Copilot capabilities into supported threat intelligence experiences in the Defender portal. Use Copilot to summarize threat intelligence, prioritize threats based on your organization's exposure, and learn more about threat actors, tools, vulnerabilities, and other threats.

For more information, see Use Microsoft Security Copilot for threat intelligence.

Use Project Perception for threat intelligence

If your organization has access to Project Perception, use the Threat Intelligence Agent to analyze threat intelligence and turn it into actionable insights for your environment. The agent can extract indicators and threat actor information, map techniques to MITRE ATT&CK, assess threat relevance to your organization, and generate KQL hunting queries.

For more information, see Threat Intelligence Agent.

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender XDR Tech Community.