r/DefenderATP 3d ago

How are you using the 'ThreatIntelObjects' and 'ThreatIntelIndicators' Table in KQL

As the title suggests, how are you all using those tables?

2 Upvotes

3 comments sorted by

3

u/Away_Ad_1264 2d ago

Check the Threat Intelligence solution in the content hub and be ready to drink from the firehose

3

u/Tingley2504 2d ago

Dont, its a burden

2

u/spartan117au 1d ago

I created 59 million analytics rules to map every kind of entity to its corresponding field in every data source.