During a threat hunt in Microsoft Sentinel, an analyst creates a custom hunting query that uses the 'externaldata' operator to reference a CSV file stored in Azure Blob Storage. The hunt identifies several suspicious IP addresses that need to be added to a threat intelligence indicator. Which method should the analyst use to persist the findings as indicators of compromise (IOCs) for automated alerting?
Trap 1: Add the IPs to a Microsoft Sentinel watchlist and reference the…
Watchlists are for temporary reference data, not for formal threat intelligence indicators.
Trap 2: Create a custom analytics rule that includes the IPs as inline…
This embeds IOCs in a rule but does not create reusable threat intelligence objects.
Trap 3: Use Azure Logic Apps to create a playbook that blocks the IPs…
This is a response action, not a method to persist IOCs for detection.
- A
Upload the CSV to a custom threat intelligence feed using the Threat Intelligence - Upload Indicators API
This makes the IPs available as threat intelligence indicators for use in detection rules.
- B
Add the IPs to a Microsoft Sentinel watchlist and reference the watchlist in an analytics rule
Why it fails: Watchlists are for temporary reference data, not for formal threat intelligence indicators.
- C
Create a custom analytics rule that includes the IPs as inline indicators
Why it fails: This embeds IOCs in a rule but does not create reusable threat intelligence objects.
- D
Use Azure Logic Apps to create a playbook that blocks the IPs automatically
Why it fails: This is a response action, not a method to persist IOCs for detection.