Event banner
Microsoft Defender Threat Intelligence and Sentinel integration deep dive
Event Ended
Thursday, Apr 13, 2023, 07:30 AM PDTEvent details
See how quick detection and response are vital to navigating today's fast-moving cyberattacks. We'll break down a cyberattack and show how Microsoft Defender Threat Intelligence, combined with Microsoft's SIEM and XDR solutions, constructs a multi-stage incident giving visibility into the attack timeline and all related events. We'll then investigate the attacker and automate mitigations to contain the damage.
This session is part of the Microsoft Secure Tech Accelerator. RSVP for event reminders, add it to your calendar, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event. |
Trevor_Rusher
Updated Dec 27, 2024
- Trevor_Rusher
Community Manager
Thank you for watching this session! We would love to hear your feedback on this event, tell us what you thought here: https://aka.ms/TechAccelSurvey3 - MS365DNinjaCopper Contributori am learning a lot from these sessions.
- Trevor_Rusher
Community Manager
Thank you for the feedback Nessa! We're really enjoying bringing these to you!
- Trevor_Rusher
Community Manager
Thanks for joining us today! We’ll continue to answer questions here in the chat for the rest of the half hour and we’ll check back through the end of the week. Thanks to everyone who was able to join us live - and to those catching up on demand!
Up next: Protecting your user identities
- Heather_Poulsen
Community Manager
- Yash_MudaliarIron ContributorIs there a way to run the hunting queries against these TIs?
- RijutaKapoor
Microsoft
Yes we do provide some sample TI hunting queries that all start with "TI map" keyword. The TI Map hunting queries are all part of the "Threat Intelligence" solution on the content hub. You can get these queries by installing the solution. The queries are completely customizable incase you need to run them against a particular data type. The queries get all indicators from the ThreatIntelligenceIndicators table in log analytics and the MDTI indicators are part of the table when you enable the MDTI connector.
- Trevor_Rusher
Community Manager
Hope you are enjoying this deep dive into Microsoft Defender Threat Intelligence and Sentinel integration. What do you like about this event? Share your feedback here in the Comments and help shape the direction of our future events on the Tech Community! - bobbobcomCopper Contributoris it possible to connect to the threat intelligence api and pull down the same TI data?
- RijutaKapoor
Microsoft
Yes these indicators are accessible through the Sentinel TI "Get API": https://learn.microsoft.com/en-us/rest/api/securityinsights/preview/threat-intelligence-indicator/get?tabs=HTTP
- Dean_GrossSilver Contributor
I don't see MDTI as a Content Hub solution in Sentinel, how do I get it? Never mind, the search in the Content Hub is not very good. I searched for threat intelligence and the solution was not found, but when I searched for Microsoft Defender, it was found.
- RijutaKapoor
Microsoft
The Microsoft Defender Threat Intelligence data connector is part of the "Threat Intelligence" solution in the content hub. The data connector is free for all Sentinel customers. Here are all the steps to enable the connector: https://learn.microsoft.com/en-us/azure/sentinel/connect-mdti-data-connector The Microsoft Defender Threat Intelligence playbooks are part of the "MDTI" solution and require a MDTI license.
- Check this documentation https://learn.microsoft.com/en-us/azure/sentinel/work-with-threat-indicators
- Dean_GrossSilver Contributorhow do we get MDTI if we don't have O365?
- dennismercer
Microsoft
You can sign up for the MDTI Premium License with the link that Michael posted.
- TI exist in M365 and as well in Microsoft Sentinel in Azure. Some customers do not have M365 but only Azure subscriptions. Then Microsoft Sentinel will be answer.
- Mike_Browning
Microsoft
Hi Dean, MDTI is a separately licensed product. You can learn more and begin a free trial here: https://aka.ms/try-it-today
- Dean_GrossSilver Contributorwe are a MSSP, do we need to buy MDTI for each Sentinel workspace we monitor or is there a way to share it across multiple workspaces?
- RijutaKapoor
Microsoft
Hi Dean, Yes the connector is a per workspace connector. You will have to enable it in all workspaces. There are ways to manage your workspaces as a MSSP that you can utilize. https://learn.microsoft.com/en-us/azure/sentinel/multiple-tenants-service-providers- Dean_GrossSilver ContributorThanks, but these instructions don't provide any guidance about how to work with MDTI for multiple workspaces, some guidance on this specific topic would be helpful.