Microsoft Integrates Threat Intelligence into Defender XDR and Sentinel
Microsoft has integrated its Threat Intelligence (MDTI) capabilities into Defender XDR and Microsoft Sentinel. This move aims to provide security analysts with real-time threat intelligence directly within their workflow, eliminating the need for a separate platform.
Previously, teams had to switch between multiple interfaces to collect threat actor information, indicators of compromise, and investigation context. This fragmented approach slowed down detection and response efforts.
The integration brings Microsoft Defender XDR entity pages up-to-date with real-time threat intelligence context. Security analysts can now view contextual information about IPs, domains, and other entities without switching between different tools or tabs.