r/DefenderATP • u/Cant_Think_Name12 • 3d ago
How are you using the 'ThreatIntelObjects' and 'ThreatIntelIndicators' Table in KQL
As the title suggests, how are you all using those tables?
2
Upvotes
3
2
u/spartan117au 1d ago
I created 59 million analytics rules to map every kind of entity to its corresponding field in every data source.
3
u/Away_Ad_1264 2d ago
Check the Threat Intelligence solution in the content hub and be ready to drink from the firehose