Summary
In this chapter, we explored the concept of TI, the new terminology and solution options, and the concept of creating and sharing TI feeds as a community effort. There are several options available for adding TI feeds to Microsoft Sentinel, and we know Microsoft is working to develop this even further. TI feeds will assist with the analysis and detection of unwanted behavior and potentially malicious activities. With many options to choose from, selecting the right feeds for your organization is an important part of configuring Microsoft Sentinel.
The next chapter introduces the Kusto Query Language (KQL), which is a powerful means to search all data collected for Microsoft Sentinel, including the TI data we just added.