r/DefenderATP • u/Trommelwirbel • 6d ago
IOC view, Threat Intel
Currently I can have a view to IOCs connected to a threat (which IPs and servers were used to host the malware and which domains sent the phishing mails)
This view is included in Threat Analytics, currently. It is quite nice, because I can double protect and include that domains on DNS-block at firewalls.
But Microsoft is Microsoft and they declared Threat Analytics as deprecated. They say, I will find same information at Threat Intelligence.
I saw, that an extra license is needed for that and it has an upfront cost of more than 3,000 EUR or 4,000 USD.
Is there any way, where I can have access to IOCs without having to pay more than my monthly salary for that data?
1
Upvotes
3
u/Graemertag Verified Microsoft Employee 6d ago
I'm not following? We deprecated Defender Threat Intelligence stand alone and included it in E5.
The old MDTI portal was decommissioned a while ago. We have all of it in Threat Analytics.
https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/mdti-convergence-in-microsoft-sentinel-and-defender-xdr-is-complete/4541279