{"id":20762,"date":"2021-10-18T11:15:02","date_gmt":"2021-10-18T18:15:02","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/azuregov\/?p=20762"},"modified":"2021-10-18T12:04:40","modified_gmt":"2021-10-18T19:04:40","slug":"defending-federal-information-systems-with-azure-sentinel-threat-intelligence-workbook","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/azuregov\/defending-federal-information-systems-with-azure-sentinel-threat-intelligence-workbook\/","title":{"rendered":"Defending federal information systems with Azure Sentinel threat intelligence workbook"},"content":{"rendered":"<p><em>This blog is co-authored by <a href=\"https:\/\/www.linkedin.com\/in\/tjbanasik\/\">TJ Banasik<\/a>, CISSP-ISSEP, ISSAP, ISSMP, Senior Program Manager; and <a href=\"https:\/\/www.linkedin.com\/in\/lilidavoudian\/\">Lili Davoudian<\/a>, Program Manager II of Microsoft Cloud &amp; AI Security.<\/em><\/p>\n<p>Threats against federal information systems are a rising concern requiring detailed understanding of threat actors, behavior, and methods. The <a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/\">Executive Order on Improving the Nation\u2019s Cybersecurity<\/a> details several requirements for removing barriers to sharing threat information, including access and insights into cyber threats and incident information. Threat intelligence is an advanced cybersecurity discipline requiring detailed knowledge of identifying and responding to an attacker based on observation of indicators in various stages of the attack cycle.<\/p>\n<p>Azure Sentinel is a cloud-native SIEM (security information event management) solution that allows customers to import threat intelligence data from various places such as paid threat feeds, open-source feeds, and from various threat intelligence sharing communities. Azure Sentinel supports open-source standards to bring in feeds from threat intelligence platforms (TIPs) across STIX &amp; TAXII. Microsoft has released the next evolution of threat hunting capabilities in the Azure Sentinel threat intelligence workbook.<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-Workbook-GIF.gif\"><img decoding=\"async\" class=\"alignnone wp-image-20764\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-Workbook-GIF.gif\" alt=\"Image Azure Sentinel Workbook GIF\" width=\"1029\" height=\"431\" \/><\/a><\/p>\n<p class=\"paragraph\" style=\"vertical-align: baseline;\"><span style=\"font-family: 'Segoe UI',sans-serif;\">Azure Sentinel threat intelligence is based on ingestion of threat indicators such as IP addresses, domains, URLs, email senders, and file hashes. This provides a starting point for building threat intelligence programs which require the ability to both ingest and correlate threat data across cloud workloads. Watch this demo for more details:<\/span><\/p>\n<p><iframe loading=\"lazy\" src=\"\/\/www.youtube.com\/embed\/SjEG7iVVBbI\" width=\"840\" height=\"473\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p><strong>Benefits<\/strong><\/p>\n<ul>\n<li>Ingest, analyze, hunt for indicators within workloads<\/li>\n<li>Free text search to hunt for IPs, hashes, emails, etc., across 50+ Microsoft telemetry components<\/li>\n<li>Advanced correlations for artificial intelligence and machine learning (AI\/ML), user entity behavior analytics (UEBA), and geospatial location of threats<\/li>\n<li>Find, fix, resolve workload weaknesses<\/li>\n<li>Query\/alert generation<\/li>\n<\/ul>\n<p><strong>Getting started<\/strong><\/p>\n<p>The Azure Sentinel threat intelligence workbook provides the capability to both ingest and correlate threat data in cloud workloads. It also provides a free text search to hunt for IPs, hashes, emails etc., across 50+ Microsoft telemetry components. There are advanced correlations for AI\/ML, UEBA, and geospatial location of threat sources. Here&#8217;s how to get started:<\/p>\n<p>1. Onboard <a href=\"https:\/\/docs.microsoft.com\/azure\/sentinel\/quickstart-onboard\">Azure Sentinel<\/a><\/p>\n<p>2. <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-threat-intelligence-tip\">Connect threat intelligence platforms<\/a><\/p>\n<p>3. <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-threat-intelligence-taxii\">Connect STIX\/TAXII feeds<\/a><\/p>\n<p>4. Access the content:\u00a0 Azure Sentinel &gt; Threat intelligence &gt; Threat intelligence workbook<\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-1.jpg\"><img decoding=\"async\" class=\"alignnone wp-image-20783\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-1-300x148.jpg\" alt=\"Image Azure Sentinel TI 8211 Image 1\" width=\"866\" height=\"427\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-1-300x148.jpg 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-1-1024x505.jpg 1024w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-1-768x379.jpg 768w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-1-1536x757.jpg 1536w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-1-2048x1010.jpg 2048w\" sizes=\"(max-width: 866px) 100vw, 866px\" \/><\/a><\/p>\n<p>5. Review the content and provide feedback through our <a href=\"https:\/\/forms.office.com\/r\/n9beey85aP\">survey<\/a><\/p>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-2.jpg\"><img decoding=\"async\" class=\"alignnone wp-image-20784\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-2-300x119.jpg\" alt=\"Image Azure Sentinel TI 8211 Image 2\" width=\"866\" height=\"342\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-2-300x119.jpg 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-2-1024x406.jpg 1024w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2021\/10\/Azure-Sentinel-TI-Image-2-1536x609.jpg 1536w\" sizes=\"(max-width: 866px) 100vw, 866px\" \/><\/a><\/p>\n<p><strong>Learn more about threat intelligence with Microsoft Security<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/azure-sentinel\/general-availability-of-azure-sentinel-threat-intelligence-in\/ba-p\/2525227\">General availability of Azure Sentinel Threat intelligence in Azure commercial and Azure Government<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/understand-threat-intelligence\">Understand threat intelligence in Azure Sentinel<\/a><\/li>\n<li><a href=\"https:\/\/www.bing.com\/aclk?ld=e8mIHbtaOUdGRIlOCkrqe44jVUCUy8kGGQn-qM3UnAsuf-wHAeYkdkFxzS4vgJKPTAl1q57OJgI0LdZ0VHWDoo1EaLo3PlZ-EcFUo4fmAqpE-8K4VOQD78y65T0_iiZ_9UpL9tD0izWc82xqzAxlTnVP7Mo1E1PiqSSdvqA_qMog2hpwYPL4GyMbDXt2FW05rIuDXKiw&amp;u=aHR0cHMlM2ElMmYlMmZ3d3cubWljcm9zb2Z0LmNvbSUyZmVuLXVzJTJmc2VjdXJpdHklMmZidXNpbmVzcyUyZiUzZmVmX2lkJTNkOWI0MTQ0ZGY2ZTYzMTNhZDE4YTYyNTgzZTFkYjU3ZWYlM2FHJTNhcyUyNk9DSUQlM2RBSUQyMjAwOTM4X1NFTV85YjQxNDRkZjZlNjMxM2FkMThhNjI1ODNlMWRiNTdlZiUzYUclM2FzJTI2bXNjbGtpZCUzZDliNDE0NGRmNmU2MzEzYWQxOGE2MjU4M2UxZGI1N2Vm&amp;rlid=9b4144df6e6313ad18a62583e1db57ef&amp;ntb=1\">Microsoft threat intelligence<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this blog with video, Lili Davoudian and TJ\u00a0Banasik, CISSP-ISSEP, ISSAP, ISSMP,\u00a0discuss and demonstrate how Azure Sentinel threat intelligence workbook can help you start building threat intelligence programs by providing the capability to ingest and correlate threat data in cloud workloads.<\/p>\n","protected":false},"author":16830,"featured_media":20798,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,29],"tags":[75,95,2405,216,315,502],"class_list":["post-20762","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azuregov","category-security","tag-azure","tag-azure-government","tag-azure-sentinel","tag-cybersecurity","tag-government","tag-security"],"acf":[],"blog_post_summary":"<p>In this blog with video, Lili Davoudian and TJ\u00a0Banasik, CISSP-ISSEP, ISSAP, ISSMP,\u00a0discuss and demonstrate how Azure Sentinel threat intelligence workbook can help you start building threat intelligence programs by providing the capability to ingest and correlate threat data in cloud workloads.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/20762","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/users\/16830"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/comments?post=20762"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/20762\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media\/20798"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media?parent=20762"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/categories?post=20762"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/tags?post=20762"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}