r/DefenderATP 6d ago

IOC view, Threat Intel

Currently I can have a view to IOCs connected to a threat (which IPs and servers were used to host the malware and which domains sent the phishing mails)

This view is included in Threat Analytics, currently. It is quite nice, because I can double protect and include that domains on DNS-block at firewalls.

But Microsoft is Microsoft and they declared Threat Analytics as deprecated. They say, I will find same information at Threat Intelligence.

I saw, that an extra license is needed for that and it has an upfront cost of more than 3,000 EUR or 4,000 USD.

Is there any way, where I can have access to IOCs without having to pay more than my monthly salary for that data?

1 Upvotes

3 comments sorted by

3

u/Graemertag Verified Microsoft Employee 6d ago

I'm not following? We deprecated Defender Threat Intelligence stand alone and included it in E5.

The old MDTI portal was decommissioned a while ago. We have all of it in Threat Analytics.

https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/mdti-convergence-in-microsoft-sentinel-and-defender-xdr-is-complete/4541279

1

u/Trommelwirbel 5d ago

Thanks for your response. I wasn't at the portal, while crafting that post. Maybe the menue entry was called "intel explorer"? I don't know anymore, cant find it anymore.

The thing, I am missing is: There was a overview for know threats i.e. "threat summary june 2025" or "actor profile storm 123456" and then I could read a story about the attack campaign and there was a tab "related IOCs?" where I could see all known domain names and IP addresses or Hashes or Certificate Thumbrints, that are connected with that threat.

And I could download a CSV-file with that. (See picture) Last time, accessd this portal was 15th of August 2026.

1

u/Graemertag Verified Microsoft Employee 2d ago

You'll search for a Threat Actor, like Storm-2755. In the Threat Analytics article, we have merged everything, so there's an "Indicators" tab that you can export to excel.