Edit

Transition to the new Threat intelligence experience in Microsoft Defender

The new Threat intelligence experience in the Microsoft Defender portal brings threat intelligence capabilities into two primary pages: Overview and Intel explorer.

If you previously used Threat Analytics, Intel management, or other Microsoft threat intelligence experiences in the Defender portal, use this article to understand the changes introduced with the new experience.

Unless otherwise described in this article, existing threat intelligence capabilities remain unchanged.

Changes to navigation

Use Threat intelligence in the Microsoft Defender portal to access:

  • Overview - Review the threats most relevant to your organization, including latest threats, high-impact threats, highest exposure threats, threat articles, and an executive summary from the Threat Intelligence Briefing Agent.
  • Intel explorer - Search, filter, and investigate threat intelligence across supported threat intelligence types.

Changes to search and filtering

Intel explorer provides keyword-based search across supported threat intelligence types.

Use filters such as targeted industry, targeted geography, and source to narrow the results. You can also use table-specific filters to filter supported attributes for the selected threat intelligence type.

Changes to threat intelligence types

Some Threat Analytics profile types use different names in the new Threat intelligence experience.

Previous Threat Analytics type Threat intelligence type
Technique Attack patterns
Actor Threat actor
Activity Campaign
Tool Tool
Vulnerability Vulnerability
OSINT Report
Core threat Report

Indicators and identities continue to appear as Indicators and Identities.

Changes to relationships

Relationship information has moved from the separate Relationships tab into the entity details experience. Relationships are now available directly within entity details instead of on a separate tab.