Choosing the right intel feeds for your needs
With Azure Sentinel, you can import TI from multiple sources to enhance the security analyst's ability to detect and prioritize known threats and IOCs. When configured, several optional features become available within the following Azure Sentinel tools:
- Analytics: This includes a set of scheduled rule templates you can enable to generate alerts and incidents based on matches of log events.
- Workbooks: This provides summarized information about the TI imported into Azure Sentinel and any alerts generated from analytics rules that match your threat indicators.
- Hunting: Hunting queries allow security investigators to use threat indicators within the context of common hunting scenarios.
- Notebooks: Notebooks can use threat indicators to assist with the investigation of anomalies and to hunt for malicious behaviors.
There are several options available to gain access to TI feeds, and you may choose to generate your...