StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 3: Perform threat hunting

Threat intelligence: TI indicators, TAXII feeds, threat analytics reports in Defender XDR

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Threat intelligence (TI) is information about attackers: who they are, how they operate, and the traces they leave. For a security operations center (SOC) it comes in two main forms. Indicators of compromise (IoCs) are concrete observables such as IP addresses, domains, URLs, file hashes and email addresses associated with malicious activity. Finished intelligence is written analysis of threat actors, campaigns, vulnerabilities and techniques, which tells you what to look for and how to defend. Indicators are easy to match automatically but go stale quickly; finished intelligence lasts longer and shapes priorities. In Microsoft Sentinel, indicators are stored as Structured Threat Information Expression (STIX) objects and managed on the threat intelligence page, where you can view, search, tag, add and expire them. They are stored in workspace tables so you can query them, and Microsoft has moved to newer STIX-based tables alongside the older ThreatIntelligenceIndicator table. Indicators have properties such as confidence, valid-from and valid-until dates, threat types and source. Expiring old indicators matters: IP addresses change owners, and stale indicators cause false positives.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan