MicrosoftDefenderThreatIntelligence
Use the Microsoft Defender Threat Intelligence integration to query enriched threat intelligence data such as articles, threat actor profiles, WHOIS records, and host-related infrastructure.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- MicrosoftDefenderThreatIntelligence
Configuration parameters
- app_id — Application ID (Client ID for Client Credentials mode)
- tenant_id — Tenant ID (required for Client Credentials mode)
- credentials —
- creds_certificate — Certificate Thumbprint
- use_managed_identities — Use Azure Managed Identities
- managed_identities_client_id —
- azure_ad_endpoint — Azure AD endpoint
- client_credentials — Use Client Credentials Authorization Flow
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (12)
- msg-defender-threat-intel-article-indicators-list — Get indicators of threat or compromise related to the contents of an article.
- msg-defender-threat-intel-article-list — Get articles including their properties and relationships.
- msg-defender-threat-intel-auth-complete — Completes the authorization process. Should be used after running the msg-defender-threat-intel-auth-start command.
- msg-defender-threat-intel-auth-reset — Reruns the authentication process.
- msg-defender-threat-intel-auth-start — Starts the authorization process. Follow the instructions in the command results.
- msg-defender-threat-intel-auth-test — Tests connectivity to Microsoft.
- msg-defender-threat-intel-host — Read the properties and relationships of a host object.
- msg-defender-threat-intel-host-reputation — Retrieves the reputation details, properties, and related information for a specified host.
- msg-defender-threat-intel-host-whois — Get the specified whoisRecord resource.
- msg-defender-threat-intel-host-whois-history — Get the history for a whoisRecord, as represented by a collection of whoisHistoryRecord resources.
- msg-defender-threat-intel-profile-indicators-list — Get Intelligence Profiles Indicators and their properties.
- msg-defender-threat-intel-profile-list — Get Intelligence Profiles including their properties and relationships.