Threat intelligence (TI) is information about attackers: who they are, how they operate, and the traces they leave. For a security operations center (SOC) it comes in two main forms. Indicators of compromise (IoCs) are concrete observables such as IP addresses, domains, URLs, file hashes and email addresses associated with malicious activity. Finished intelligence is written analysis of threat actors, campaigns, vulnerabilities and techniques, which tells you what to look for and how to defend. Indicators are easy to match automatically but go stale quickly; finished intelligence lasts longer and shapes priorities. In Microsoft Sentinel, indicators are stored as Structured Threat Information Expression (STIX) objects and managed on the threat intelligence page, where you can view, search, tag, add and expire them. They are stored in workspace tables so you can query them, and Microsoft has moved to newer STIX-based tables alongside the older ThreatIntelligenceIndicator table. Indicators have properties such as confidence, valid-from and valid-until dates, threat types and source. Expiring old indicators matters: IP addresses change owners, and stale indicators cause false positives.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.