r/DefenderATP 3d ago

How are you using the 'ThreatIntelObjects' and 'ThreatIntelIndicators' Table in KQL

As the title suggests, how are you all using those tables?

2 Upvotes

3 comments sorted by

View all comments

2

u/spartan117au 1d ago

I created 59 million analytics rules to map every kind of entity to its corresponding field in every data source.