services / Azure / Microsoft Sentinel threat intelligence indicator
An individual threat-intelligence indicator (IOC) in Microsoft Sentinel that detections match ingested telemetry against.
Indicators are a detection input; altering or removing them narrows coverage but does not disable the platform, so this is MEDIUM.
Microsoft.SecurityInsights/threatintelligence/indicators/write
Writing an indicator lets an attacker inject false IOCs or alter existing ones, poisoning detection logic and potentially whitelisting their own infrastructure.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog