Skip to main content

Cyware Threat Intelligence eXchange

Microsoft Defender Threat Intelligence

Connector Category: Enrichment Tool

About Integration

CTIX integrates with Microsoft Defender Threat Intelligence to enhance threat data by delivering critical insights into IPs, domains, and vulnerabilities. This enrichment helps you gain deeper context about cyber threats, enabling more informed decision-making and improved response to potential security incidents.

Configure Microsoft Defender Threat Intelligence as an Enrichment Tool

Configure MDTI in Intel Exchange to enrich IP address, domain and vulnerabilities.

Before you Start

  • Ensure that you have the base URL and API token of your MDTI account.

  • Ensure that your user group has Create, Update, and View permissions for enrichment tools and their associated policies in Intel Exchange.

    Note

    Ensure that the API key includes the permissions to retrieve threat data details.

Steps 

To configure MDTI as an enrichment tool in Intel Exchange, follow these steps:

  1. Sign in to Intel Exchange and go to Administration > Enrichment Management > Enrichment Tools

  2. Search and select the Microsoft Defender Threat Intelligence enrichment tool. 

  3. Click Add Account and enter the following details:

    • Account Name: Enter a unique account name to identify the instance. For example Microsoft Defender Threat Intelligence Prod.

    • Base URL: Enter the base URL of your Microsoft Defender Threat Intelligence instance. The default base URL is https://graph.microsoft.com/v1.0/security/threatIntelligence/.

    • Client ID: Enter the client ID to authenticate your application on the server.

    • Client Secret: Enter the client secret to authenticate your client APIs.

    • Tenant ID: Enter the tenant ID associated with your Microsoft Defender Threat Intelligence account to establish the connection.

    • Verify SSL: Enable this option to validate the SSL certificate and secure the connection between Intel Exchange and MDTI servers. This option is enabled by default.

      Note

      Cyware recommends you select Verify SSL. If you disable this option, Intel Exchange may configure an instance for an expired SSL certificate. This may not establish the connection properly and Intel Exchange will not be able to notify you in case of a broken or improper connection.

  4. Click Save.

After successfully adding an account, you can view and enable MDTI feed enrichment types. You can also configure a quota to set a limit on the number of enrichment request the MDTI account can make. Once the quota is exhausted, no further enrichment requests can be made until the quota resets for the next quota duration. For more details, refer to Define Quota in Configure Enrichment Tools.

To understand the number of API calls and quota units consumed by the MDTI enrichment tool per polling, refer to the following table.

Enrichment Tool

Feed Enrichment Type

No. of API calls

Quota Consumed

MDTI

Domain 

3

3

IP

3

3

Vulnerability 

1

1

You can configure an enrichment policy to automatically enrich threat data objects using the MDTI enrichment tool. For more information, refer to Enrichment Policy.