MicrosoftMicrosoft Sentinel

    Threat Intelligence

    Threat intelligence management that enriches detection across Sentinel.

    Microsoft Sentinel Threat Intelligence ingests, manages, and operationalises threat intelligence — indicators, threat actors, and Microsoft’s vast first-party intelligence — to enrich detection, hunting, and investigation across the SOC. It turns intelligence into detections and context that make every alert more actionable. Faltrox operates it as the threat-intelligence layer of a managed SOC.

    Overview

    What Threat Intelligence is

    Threat intelligence only helps if it is operationalised — integrated into detection and investigation rather than sitting in a feed. Microsoft Sentinel Threat Intelligence brings intelligence into the SOC: it ingests indicators and threat context from Microsoft’s first-party intelligence and third-party and open feeds, manages them, and uses them to enrich detection, hunting, and investigation.

    It supports importing and managing threat indicators (STIX/TAXII and more), curating Microsoft’s vast threat intelligence, matching indicators against your data to generate detections, and enriching incidents with actor and campaign context — so an alert carries the intelligence needed to prioritise and act. Faltrox operates it as the threat-intelligence layer of the managed SOC it runs, turning intelligence into detections and context.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    Microsoft Intelligence

    Operationalises Microsoft’s vast first-party threat intelligence.

    02

    Third-Party & Open Feeds

    Ingests third-party and open-source intelligence via STIX/TAXII.

    03

    Indicator Matching

    Matches indicators against your data to generate detections.

    04

    Actor & Campaign Context

    Enriches incidents with threat-actor and campaign context.

    05

    Enriched Detection

    Turns intelligence into detections and prioritisation across the SOC.

    06

    Indicator Management

    Imports, curates, and manages threat indicators centrally.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      Ingest

      Threat indicators and context are ingested from Microsoft, third-party, and open feeds.

    2. 02

      Curate

      Indicators are managed and curated centrally for relevance and quality.

    3. 03

      Match

      Indicators are matched against your Sentinel data to generate detections.

    4. 04

      Enrich

      Incidents are enriched with actor and campaign context to prioritise and guide response.

    5. 05

      Operate

      Faltrox operationalises intelligence into detections and context as part of a managed SOC.

    Capabilities

    Key capabilities

    Intelligence Ingestion

    Ingests Microsoft first-party, third-party, and open-source intelligence via STIX/TAXII.

    Indicator Management

    Imports, curates, and manages threat indicators centrally.

    Indicator Matching

    Matches indicators against your data to generate high-fidelity detections.

    Actor & Campaign Context

    Enriches incidents with threat-actor and campaign context.

    Microsoft Threat Intelligence

    Operationalises Microsoft’s vast global threat intelligence.

    Detection Enrichment

    Makes every alert more actionable with intelligence context.

    Hunting Support

    Supports proactive threat hunting with curated intelligence.

    Sentinel Integration

    Integrated across the Sentinel platform for detection and investigation.

    Works with

    Part of the platform

    Microsoft products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Microsoft Threat Intelligence for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01What does threat intelligence in Sentinel do?

    It operationalises intelligence — ingesting indicators and threat context from Microsoft, third-party, and open feeds, managing them, and using them to enrich detection, hunting, and investigation. It turns intelligence into detections and context rather than leaving it in an unread feed.

    02Does it use Microsoft’s own intelligence?

    Yes — it operationalises Microsoft’s vast first-party threat intelligence alongside third-party and open-source feeds, giving detections and investigations the context of one of the world’s largest intelligence operations.

    03How does intelligence become detections?

    Ingested indicators are matched against your Sentinel data to generate detections, so when a known-malicious indicator appears in your environment it surfaces as an alert — turning threat intelligence into active detection rather than passive reference.

    04How does it help investigation?

    It enriches incidents with threat-actor and campaign context, so an analyst investigating an alert sees who is likely behind it and how they operate — which speeds prioritisation and guides response. Faltrox applies that context in the SOC.

    05How does Faltrox operate it?

    We operationalise threat intelligence into the managed SOC we run — ingesting and curating feeds, generating detections from indicators, and enriching incidents with context, so intelligence actively improves detection and response.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us