services / Azure / Microsoft Sentinel threat intelligence
Threat-intelligence (STIX) data in Microsoft Sentinel, the indicators and IOCs used to match ingested telemetry against known-malicious infrastructure.
TI is a detection input rather than the full SIEM; degrading it narrows detection coverage but does not disable the platform, so this resource type is MEDIUM.
Microsoft.SecurityInsights/threatintelligence/write
Writing threat intelligence lets an attacker inject false indicators or alter existing ones, poisoning detection logic and potentially whitelisting their own infrastructure.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog