services / Azure / Microsoft Sentinel threat intelligence
Threat-intelligence (STIX) data in Microsoft Sentinel, the indicators and IOCs used to match ingested telemetry against known-malicious infrastructure.
TI is a detection input rather than the full SIEM; degrading it narrows detection coverage but does not disable the platform, so this resource type is MEDIUM.
Microsoft.SecurityInsights/threatintelligence/delete
Deleting threat intelligence removes indicators the SIEM matches against, degrading detection coverage of known-malicious infrastructure.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog