Threat Intelligence
Microsoft Sentinel threat intelligence stores, manages, queries, and uses threat indicators and STIX objects from Microsoft feeds, TAXII feeds, TIP integrations, manual analyst additions, and custom upload API ingestion.
capabilitiesCurrent
Relationships
Configuration Methods
| Method | Support | Reference or Gap |
|---|---|---|
| Portal | Supported | Reference |
| PowerShell | Gap | No product-specific PowerShell automation surface is recorded for this capability yet. |
| REST API | Supported | Reference |
| Graph | Gap | No supported Microsoft Graph configuration surface is recorded for this capability yet. |
| ARM | Gap | IOC ingestion is an operational STIX upload API flow, not ARM desired state. |
| Bicep | Gap | Use the Sentinel Threat Intelligence upload API for custom IOC ingestion. |
| Terraform | Gap | Threat intelligence indicators are operational data. Ingest with the Sentinel STIX upload API from a pipeline/script step, not Terraform. |
| GitHub Actions | Supported | Reference |
| Azure DevOps | Supported | Reference |