Skip to content
10 New Indicators Skills Can Now Leverage MDTI Indicator Data | Microsoft Defender

10 New Indicators Skills Can Now Leverage MDTI Indicator Data | Microsoft Defender

Written By Anoop C Nair
Last Updated November 22, 2024
Posted In Copilot
SHARE

Ten New Indicators Skills can now leverage MDTI Indicator Data. Yes! This is excellent news for Security Copilot customers. Using Threat Intelligence (TI) sources, they can develop a full view of risks and increase their awareness of attacker tools and methods and how they affect the organisation.

Microsoft’s Security Copilot has improved in detecting threats. At Microsoft Ignite 2024, they announced new features that are generally available to Security Copilot users. They can now access more threat intelligence sources to understand how attackers work and how they target their organization.

Microsoft Defender Threat Intelligence (MDTI) is a powerful platform for storing threat intelligence, including incident response, threat hunting, vulnerability management, and threat intelligence analyst workflows. It helps professionals analyze and respond to security signals.

MDTI Indicator Data is now in Public preview. You can now use ten new indicators skills to control threat intelligence. In this post, I will briefly explain the ten new indicators skills that can leverage MDTI Indicator Data.

Patch My PC
10 New Indicators Skills Can Now Leverage MDTI Indicator Data | Microsoft Defender - Fig.1
10 New Indicators Skills Can Now Leverage MDTI Indicator Data | Microsoft Defender – Fig.1

What are Indicators of Compromise (IoC)?

An indicator of compromise (IoC) indicates that someone might have violated the organization’s network or computer. It shows that something crucial like malware, compromised credentials, or data exfiltration has already happened. Security experts search for the event logs and security tools to stop the attack and fix the damage. After everything is fixed, they research how the attack happened so that the organization’s security can strengthen and reduce the risk. 

Ten New Indicators Skills Can Now Leverage MDTI Indicator Data

Ten new indicators skills to control threat intelligence. These indicators can link any indicator of compromise (IoC) to related data, which can help signal the attacks. This allows security experts to investigate attacks more efficiently and defend against threats. These new skills use two main types of threat information.

Two Main Types of Threat Information
In-depth Indicators data
Indicators Metadata
10 New Indicators Skills Can Now Leverage MDTI Indicator Data | Microsoft Defender – Table 1

In-depth Indicators Data

Security Copilot can link any indicator of compromise (IoC) with all threat intelligence related to it in MDTI. It includes articles, Intel profiles, and summary data from Microsoft’s file and URL analysis. Sometimes, a critical situation requires a quick response, such as current information on the attacker and the nature of the attack. This data can also level up experts by preparing the needed next steps charted in MDTI to help them agree with the incident quickly and efficiently. 

The following image is an example of an indicator linked to several IP addresses, two articles, and three Intel profiles.

10 New Indicators Skills Can Now Leverage MDTI Indicator Data | Microsoft Defender - Fig.2 (Image credit to MS)
10 New Indicators Skills Can Now Leverage MDTI Indicator Data | Microsoft Defender – Fig.2 (Image credit to MS)

Indicators Metadata

MDTI has advanced Internet data sets. These data sets help Security Copilot link any IoC to the associated infrastructure. Core and derived data sets are made from Internet data collected and examined worldwide. Linking IoC to the associated infrastructure can help analysts find new threat tools and defend the threat activity before it affects the organisation.

  • Core Data Sets: It includes Resolutions, WHOIS information, SSL Certificates, Subdomains, DNS, Reverse DNS, and Services
  • Derived Data Sets: Trackers, Components, Host Pairs, and Cookies.
10 New Indicators Skills Can Now Leverage MDTI Indicator Data | Microsoft Defender - Fig.3 (Image credit to MS)
10 New Indicators Skills Can Now Leverage MDTI Indicator Data | Microsoft Defender – Fig.3 (Image credit to MS)

Resources

Need Further Assistance or Have Technical Questions? 

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.  

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc. 

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Copilot

Microsoft Introduces AI-Powered Copilot Agent Mode in Outlook

Key Takeaways In this post, we are discussing Microsoft Introduces AI-Powered Copilot Agent Mode in Outlook. Microsoft has launched a new update for Copilot in Outlook that helps users manage emails and meetings more easily. The new Agent mode allows Copilot to work more actively in the background instead of only helping with simple tasks […]

AC Anoop C Nair 4 min read
Copilot

1300 Plus SharePoint Servers Still Exposed to Critical Zero Day Vulnerability

Key Takeaways In this post, we are discussing1300 Plus SharePoint Servers Still Exposed to Critical Zero Day Vulnerability. Microsoft recently released security updates to fix a critical vulnerability affecting its SharePoint platform, but a number of systems are still at risk. Even after the patch rollout, over 1,300 servers remain exposed online without protection. 1300 […]

AC Anoop C Nair 3 min read
Copilot

Enhancing Threat Detection and Identity Protection with AI Security Copilot Agents

Hey, let’s discuss about Enhancing Threat Detection and Identity Protection with AI Security Copilot Agents. Security Copilot Agents are smart AI helpers for IT and security teams. They take care of repeated work, so people can spend more time protecting the company from cyber attacks. This makes security work faster and easier. These agents are […]

AC Anoop C Nair 3 min read
AI

Why Is Enterprise AI Rollout Stuck? Transformational Strategy or Just Small Steps?

Why Is Enterprise AI Rollout Stuck? Transformational Strategy or Just Small Steps? Most companies are spending a lot of money on Generative AI, but the results are not matching the expectations. According to MIT, 95% of big AI projects are failing because they are not giving any real business results. Only a small group of companies about […]

AC Anoop C Nair 5 min read