capability

Threat Intelligence

Microsoft Sentinel threat intelligence stores, manages, queries, and uses threat indicators and STIX objects from Microsoft feeds, TAXII feeds, TIP integrations, manual analyst additions, and custom upload API ingestion.

capabilitiesCurrent

Relationships

Configuration Methods

MethodSupportReference or Gap
PortalSupported Reference
PowerShellGapNo product-specific PowerShell automation surface is recorded for this capability yet.
REST APISupported Reference
GraphGapNo supported Microsoft Graph configuration surface is recorded for this capability yet.
ARMGapIOC ingestion is an operational STIX upload API flow, not ARM desired state.
BicepGapUse the Sentinel Threat Intelligence upload API for custom IOC ingestion.
TerraformGapThreat intelligence indicators are operational data. Ingest with the Sentinel STIX upload API from a pipeline/script step, not Terraform.
GitHub ActionsSupported Reference
Azure DevOpsSupported Reference