
Threat Intelligence (TI) provides this context. Instead of merely reporting that an incident has occurred, it reveals who is behind a given technique, what tools they use, and what the attacker’s next move might be. This allows the team to focus on confirmed high-risk incidents rather than analyzing each alert individually.
At ISCG, we implement Threat Intelligence within Microsoft’s native security ecosystem. We translate information about new attacks into rules and automations that block malicious traffic in your infrastructure—without requiring you to build your own SOC team from scratch.
How does TI differ from regular alerts?
Raw data, such as IP addresses, hashes of malicious files, or suspicious domains, are indicators of compromise (IoC). Their value becomes apparent only when a single indicator from your environment is linked to an entire known series of attacks (a campaign). The system can then block the remaining attack vectors from the same series before they are exploited.
The greatest value of Threat Intelligence, therefore, is not just another database of indicators. It is the ability to link a single incident to the broader picture of a specific adversary’s activities.
Three Levels of Analytics: From Metrics to Management Decisions
For threat data to have operational value, it must reach the right recipients and meet their needs. Three levels of analysis are most commonly identified.
Tactical - for safety engineers
At the tactical level, IoC indicators are used to directly feed security systems such as firewalls, spam filters, and EDR. This enables the automatic blocking of traffic from C2 (Command and Control) servers used by attackers.
Operations - for IT architects and SOC professionals
The operational level, on the other hand, focuses on tactics, techniques, and procedures (TTPs). It allows you to map the environment to the MITRE ATT&CK framework and assess whether current policies (including those in Entra ID) would have detected the methods used in recent high-profile breaches.
Strategic - for the CISO and the Board of Directors
Only the strategic level addresses questions that are relevant from a business perspective. The executive board isn’t interested in IP addresses, but rather in trends, new attack vectors in a given industry, and their impact on the organization’s risk. It is on this basis that the CISO can justify the budget, set priorities for patching systems, or change access policies for external vendors.
Not sure if your organization is already taking advantage of threat intelligence capabilities?
In many organizations, Threat Intelligence features are included in their Microsoft licenses but remain unused. It’s worth checking first what you can already use today and where automation will have the greatest impact.
Where does this happen within the Microsoft ecosystem?
For most organizations, this means two significant changes. First and foremost, MDTI is no longer just another product to buy, but a feature that can often be deployed within an organization’s existing environment. MDTI capabilities are available with the Microsoft 365 E5 Security license at no additional cost, although many customers still aren’t taking advantage of them. Equally important is that analysts work in the same tools as before (Microsoft Defender and Microsoft Sentinel)—without having to switch between different consoles.
Microsoft Sentinel remains the central component. The platform retrieves threat indicators and cross-references them with logs from across the entire infrastructure—from email to workstations to cloud applications. If an employee clicks a link that was globally classified as part of a phishing campaign an hour earlier, Sentinel will escalate the incident and can isolate the infected device from the network using automation scenarios (Playbooks) integrated with Microsoft Defender.
The result is simple: the security team focuses on confirmed high-risk incidents instead of analyzing each alert individually. This is an effective way to reduce the occurrence of alert fatigue.
However, it’s worth keeping one limitation in mind. The TI data connector and the so-called. matching analytics In Microsoft Sentinel, these features are available without additional premium licenses. Some of the more advanced playbooks that enhance incident response require a higher licensing tier. The scope of available features depends on the licenses you hold, which is why we begin every project by reviewing them.
How can I get started without dragging out the project?
To prepare the implementation plan, all we need is:
- an overview of current security tools (firewalls, EDR, and email protection),
- review your Microsoft license to see which features you can use without making additional purchases,
- lists of critical systems and processes requiring priority monitoring,
- information about the Threat Intelligence sources used—whether commercial or open-source.
FAQ - Threat Intelligence
These are the digital traces left behind by attackers: IP addresses of malicious servers, phishing domains, file names, and their unique cryptographic hashes. They feed into security systems so that these systems can proactively block known malicious traffic.
No. Maintaining a dedicated 24/7 team is costly. Threat indicators can be integrated directly with Sentinel and Microsoft Defender to block threats automatically, or you can use the SOC as a Service/Threat Intelligence as a Service model.
A penetration test is a one-time, controlled simulation that identifies vulnerabilities at a given point in time. IT is a continuous process—it provides up-to-date insight into how real adversaries operate before they strike.
Yes. Traditional antivirus solutions rely primarily on known signatures, whereas XDR provides context regarding tactics, techniques, and procedures (TTPs). This allows XDR systems to detect unusual sequences of actions even when a patch for a given attack is not yet available.
Based on its own telemetry. According to the Microsoft Digital Defense Report 2025, Microsoft processes over 100 trillion security signals per day and scans approximately 5 billion emails for malware and phishing. Data also comes from Microsoft Defender detections, the work of incident response teams, and open-source intelligence (OSINT) sources.
Yes. Microsoft Sentinel collects and analyzes logs from third-party devices—including Fortinet and Palo Alto firewalls and on-premises Linux servers —using the same threat intelligence as for resources running in the Microsoft cloud.
Not sure if Threat Intelligence features are already available in your Microsoft environment, or which elements you should automate first?
Let's start by reviewing your current licenses and architecture. Based on that, we'll show you what you can run without making any additional purchases and how to plan your next steps.
Learn about our other services

Business applications
Services for applications and turnkey solutions in the area of process digitization and modern work environment.

Full support and optimization of IT infrastructure, ensuring stable development of your business.
IT infrastructure

Security of deployment and maintenance of Microsoft 365 and Azure services that enable flexible management and cost optimization.



