Edit

Share via


Get access to IOCs in threat analytics in Microsoft Defender (preview)

Applies to:

  • Microsoft Defender XDR

Important

Some information in this article relates to a prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.

Each threat analytics report includes an indicators section that lists all indicators of compromise (IOCs) associated with the threat. Microsoft researchers update these IOCs in real time as they find new evidence related to the threat. This information helps your security operations center (SOC) and threat intelligence analysts with remediation and proactive hunting. The list also retains expired IOCs, so you can investigate past threats and understand their impact in your environment.

Because IOCs are valuable information in the context of prevalent threats and threat campaigns, only verified Microsoft Defender customers can access them. This article explains how you can check if you have access to the indicators section and how you unlock it if you don't.

View IOCs in threat analytics

To access the indicators section, go to the Threat analytics page, open the report about the tracked threat, and select the Indicators tab.

If you're a verified customer, you can immediately see the list of IOCs displayed in this section.

Screenshot of the Indicators tab in a threat analytics report.

Otherwise, the page informs you that access to indicators is restricted.

Screenshot of a restricted Indicators tab in a threat analytics report.

Unlock access to indicators

To unlock the indicators section, follow these steps:

  1. On the Indicators page, select Complete Verification
  2. On the verification page that opens, provide the required information and supporting documents, if applicable
  3. Select Submit verification request

The verification process might take at least an hour. After the process completes, refresh the Indicators tab. If your tenant is validated successfully, you see the list of IOCs displayed in this section.

Note

In some cases, we might require additional information during the verification process. We communicate these requirements through email.

If you still don't have access to the Indicators section after going through the verification process, contact the email address displayed on the page.

Screenshot of a restricted Indicators tab in a threat analytics report showing the email address to contact.

See also

Tip

Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender XDR Tech Community.