Microsoft rolled out its enhanced threat intelligence and external attack surface management services, designed to track threat actors’ activities and patterns and offer an outside-in view of the user’s attack surface. 

Microsoft Defender Threat Intelligence service is based on capabilities from the company’s RiskIQ acquisition, security information and signal Microsoft tracks, and analysis from former RiskIQ security research teams along with Microsoft’s nation-state tracking team, Threat Intelligence Center and the Microsoft 365 Defender security research teams. 

“The volume, scale, and depth of intelligence is designed to empower security operations centers (SOCs) to understand the specific threats their organization faces and to harden their security posture accordingly,” Vasu Jakkal, Corporate VP of compliance, identity, management and privacy at Microsoft Security, noted in a blog post. 

The tech giant bought cybersecurity software maker RiskIQ last summer. The RiskIQ technology discovers an enterprise’s entire attack surface, including known and unknown devices, across clouds, on-premises data centers, and the supply chain. The platform provides visibility from the network to the application layer and can detect and respond to threats and vulnerabilities across all external assets. 

All of that intelligence supported by artificial intelligence and machine learning capabilities will enhance the existing threat detection capabilities of Microsoft Sentinel and Microsoft Defender products, the vendor claims.

On top of those existing security services, the new threat intelligence service will provide real-time data that updates daily from over 43 trillion security signals that Microsoft cloud processes and analyzes, along with 35 ransomware families, more than 250 nation states, and other threat actors the company tracks, according to Jakkal.

The service analyzes the data to visualize changes in infrastructure and connections, identify and monitor adversaries and their toolkits, and dive deep into the breaches or alerts. It can also explore specific alerts and help block the entire toolkit of a known adversary.

“Customers can access a library of raw threat intelligence detailing adversaries by name, correlating their tools, tactics, procedures (TTPs), and can see active updates within the portal as new information is distilled from Microsoft’s security signals and experts,” Jakkal explained.

Microsoft Security Offers Outside-In View

In addition to the threat intelligence service, Microsoft also announced the external attack surface management to help organizations “see their business the way an attacker can,” built on the RiskIQ platform’s visibility capabilities, Jakkal claims.

“That outside-in view delivers even deeper insights to help organizations predict malicious activity and secure unmanaged resources.”

The services offer daily internet and connection scan, internet-facing resources discovery including the agentless and unmanaged assets, and mitigation recommendations, which enables users to bring those unknown endpoints, assets, and other resources to their security information and event management (SIEM) and extended detection and response (XDR) tools, Jakkal added.

Customers can provision the external attack surface management service within their subscription in Microsoft Azure and are billed per device.