{"id":21077,"date":"2022-05-09T07:09:40","date_gmt":"2022-05-09T14:09:40","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/azuregov\/?p=21077"},"modified":"2022-05-09T07:20:42","modified_gmt":"2022-05-09T14:20:42","slug":"ingest-and-search-indicators-across-data-with-the-microsoft-sentinel-threat-intelligence-workbook","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/azuregov\/ingest-and-search-indicators-across-data-with-the-microsoft-sentinel-threat-intelligence-workbook\/","title":{"rendered":"Jumpstart threat intelligence programs with the Microsoft Sentinel Threat Intelligence Workbook"},"content":{"rendered":"<p>We\u2019re releasing the next evolution of the Microsoft Sentinel Threat Intelligence Workbook. This solution provides enhanced capabilities in indicator ingestion and indicator search, empowering organizations to centralize and correlate threat data across their workloads and operationalize these insights for investigation and response. As a result, this workbook serves as a starting point for building threat intelligence programs.<\/p>\n<p>For example, Indicator Search provides a free-text search of indicators (IP address, file, hash, email address, username) to determine:<\/p>\n<ul>\n<li>Indicators in your data<\/li>\n<li>Pattern of the indicator over time<\/li>\n<li>Reporting threat intelligence feed and details<\/li>\n<li>Security incidents for investigation and response<\/li>\n<\/ul>\n<p><strong>Learn more by watching the demo:<\/strong><\/p>\n<p><iframe loading=\"lazy\" title=\"YouTube video player\" src=\"\/\/www.youtube.com\/embed\/4Bet2oVODow\" width=\"600\" height=\"355\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><span data-mce-type=\"bookmark\" style=\"display: inline-block; width: 0px; overflow: hidden; line-height: 0;\" class=\"mce_SELRES_start\">\ufeff<\/span><\/iframe><\/p>\n<p><strong>Use cases<\/strong><\/p>\n<p>There are several use cases for the Microsoft Sentinel Threat Intelligence Workbook depending on user roles and requirements. Common use cases include threat hunting, developing alerting, and conducting research with custom reporting.<\/p>\n<p>The workbook is organized into two sections:<\/p>\n<ul>\n<li><strong>Indicators Ingestion:<\/strong> Evaluate indicators onboarded, threat feeds, and confidence ratings.<\/li>\n<li><strong>Indicator Search:<\/strong> Free text search indicators across your cloud workloads.<\/li>\n<\/ul>\n<p><strong>Benefits<\/strong><\/p>\n<ul>\n<li>Ingest, analyze, hunt for indicators within cloud, on-premises, multi-cloud, first- and third-party workloads<\/li>\n<li>Free text search to hunt for IPs, hash, user account, emails, etc., across your data<\/li>\n<li>Investigate and respond to threat intelligence indicators<\/li>\n<\/ul>\n<p><strong>Audience<\/strong><\/p>\n<ul>\n<li><strong>Threat Intelligence Professionals:<\/strong> Investigations<\/li>\n<li><strong>SecOps:<\/strong> Alert \/ automation building<\/li>\n<li><strong>MSSP:<\/strong> Consultants, managed service providers<\/li>\n<\/ul>\n<p><strong>Getting started<\/strong><\/p>\n<ol>\n<li><a href=\"https:\/\/docs.microsoft.com\/azure\/sentinel\/quickstart-onboard\">Onboard Microsoft Sentinel<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-threat-intelligence-tip\">Connect threat intelligence platforms<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/connect-threat-intelligence-taxii\">Connect STIX\/TAXII feeds<\/a><\/li>\n<li>Update workbook version\n<ol style=\"list-style-type: lower-alpha;\">\n<li>Microsoft Sentinel &gt; Workbooks &gt; Search \u201cThreat Intelligence\u201d &gt; Select &#8220;Update&#8221; in bottom right<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/05\/Threat-Intelligence-Workbook-2-May-2022.gif.png\"><img decoding=\"async\" class=\"alignnone wp-image-21079\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/05\/Threat-Intelligence-Workbook-2-May-2022.gif-300x208.png\" alt=\"Image Threat Intelligence Workbook 2 8211 May 2022 gif\" width=\"443\" height=\"307\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/05\/Threat-Intelligence-Workbook-2-May-2022.gif-300x208.png 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/05\/Threat-Intelligence-Workbook-2-May-2022.gif.png 768w\" sizes=\"(max-width: 443px) 100vw, 443px\" \/><\/a><\/p>\n<ol>\n<li value=\"5\">Access workbook\n<ol style=\"list-style-type: lower-alpha;\">\n<li>Microsoft Sentinel &gt; Threat Intelligence &gt; Threat Intelligence Workbook<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<ol>\n<li value=\"6\">Review the content and provide feedback through our <a href=\"https:\/\/forms.office.com\/r\/n9beey85aP\">survey.<\/a><\/li>\n<\/ol>\n<p><strong>Learn more about threat intelligence with Microsoft Security<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/azure-sentinel\/general-availability-of-azure-sentinel-threat-intelligence-in\/ba-p\/2525227\">General availability of Microsoft Sentinel threat intelligence in Azure commercial and Azure Government<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/understand-threat-intelligence\">Understand threat intelligence in Microsoft Sentinel<\/a><\/li>\n<li><a href=\"https:\/\/www.bing.com\/aclk?ld=e8mIHbtaOUdGRIlOCkrqe44jVUCUy8kGGQn-qM3UnAsuf-wHAeYkdkFxzS4vgJKPTAl1q57OJgI0LdZ0VHWDoo1EaLo3PlZ-EcFUo4fmAqpE-8K4VOQD78y65T0_iiZ_9UpL9tD0izWc82xqzAxlTnVP7Mo1E1PiqSSdvqA_qMog2hpwYPL4GyMbDXt2FW05rIuDXKiw&amp;u=aHR0cHMlM2ElMmYlMmZ3d3cubWljcm9zb2Z0LmNvbSUyZmVuLXVzJTJmc2VjdXJpdHklMmZidXNpbmVzcyUyZiUzZmVmX2lkJTNkOWI0MTQ0ZGY2ZTYzMTNhZDE4YTYyNTgzZTFkYjU3ZWYlM2FHJTNhcyUyNk9DSUQlM2RBSUQyMjAwOTM4X1NFTV85YjQxNDRkZjZlNjMxM2FkMThhNjI1ODNlMWRiNTdlZiUzYUclM2FzJTI2bXNjbGtpZCUzZDliNDE0NGRmNmU2MzEzYWQxOGE2MjU4M2UxZGI1N2Vm&amp;rlid=9b4144df6e6313ad18a62583e1db57ef&amp;ntb=1\">Microsoft threat intelligence | Unparalleled threat detection<\/a><\/li>\n<\/ul>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li style=\"list-style-type: none;\"><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>We\u2019re releasing the next evolution of the Microsoft Sentinel Threat Intelligence Workbook. This solution provides enhanced capabilities in indicator ingestion and indicator search, empowering organizations to centralize and correlate threat data across their workloads and operationalize these insights for investigation and response. As a result, this workbook serves as a starting point for building threat [&hellip;]<\/p>\n","protected":false},"author":62910,"featured_media":21092,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2,1,14],"tags":[75,189,216,315,3460,502],"class_list":["post-21077","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-announcements","category-azuregov","category-learning","tag-azure","tag-compliance","tag-cybersecurity","tag-government","tag-microsoft-sentinel","tag-security"],"acf":[],"blog_post_summary":"<p>We\u2019re releasing the next evolution of the Microsoft Sentinel Threat Intelligence Workbook. This solution provides enhanced capabilities in indicator ingestion and indicator search, empowering organizations to centralize and correlate threat data across their workloads and operationalize these insights for investigation and response. As a result, this workbook serves as a starting point for building threat [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/21077","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/users\/62910"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/comments?post=21077"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/21077\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media\/21092"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media?parent=21077"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/categories?post=21077"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/tags?post=21077"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}