Boost Your Threat Intel Game with Microsoft Sentinel’s New Curation at Scale
Updated Feb 14, 2025
Version 1.0Great feature but I have to ask, if a feed is known to generate a lot of false positives, why is Microsoft even including it?
Because this blog talks about ingesting your own TI sources which you control yourself, be that via TAXII or manual upload. Many companies like to integrate with free TI sources which are more prone to less qualitative IOC's, and this may help further control data ingestion.