https://catalogartifact.azureedge.net/publicartifacts/intel471inc1641226539011.intel471_threat_intelligence-4c303cd0-0820-4cd0-b500-ef3966901a55/image3_intel471216.png
Intel 471 Threat Intelligence
by Intel 471 Inc.
Just a moment, logging you in...
Intel 471 malware indicators plus 25 threat hunt packages for Microsoft Sentinel.
Intel 471 Threat Intelligence brings malware intelligence and behavioral threat hunt packages into Microsoft Sentinel.
The solution pairs two capabilities: near real-time malware indicators for detection and enrichment, and expertly-crafted behavioral hunt packages for proactive hunting. Both deploy turn-key into your existing Microsoft Sentinel workspace — no additional infrastructure required.
Malware intelligence
The core of Intel 471 Malware Intelligence is the unique and patented Malware Emulation and Tracking System (METS). METS provides ongoing surveillance of malware activity at the command and control level, delivering near real-time insights and deep context in support of numerous cybersecurity and intelligence use cases, such as security operations (NOC/SOC), threat hunting, incident response, campaign tracking, and third-party supplier and vendor risk.
The included playbook ingests those indicators directly into Microsoft Sentinel as STIX 2.1 objects using the Threat Intelligence Upload STIX Objects API, so they land in the ThreatIntelIndicators table and are immediately available to analytics rules, hunting and workbooks. Indicators are pulled incrementally from either the Verity471 or the Titan API — command-and-control IP addresses, URLs and file hashes, carrying through confidence, malware family labels, kill chain phases and expiration. API credentials are held in Azure Key Vault and every connection authenticates with the logic app's system-assigned managed identity, so no keys or connection strings are stored in the playbook itself.
Behavioral threat hunting
This solution includes 25 hunt packages from HUNTER, Intel 471's threat hunting platform — content gathered from a wide array of intelligence sources and put through structured analysis by a team of subject matter experts, then written as ready-to-run Microsoft Sentinel hunting queries.
The community hunt packages cover the latest emerging threats and can be access by reaching out to sales@intel47.com for a community account. The full library of over 800 behavioral threat hunt packages is available with an active Intel 471 subscription.
Because they target attacker behavior rather than infrastructure, these hunts keep working after an adversary rotates domains, rebuilds servers or recompiles a payload. Coverage spans 27 MITRE ATT&CK techniques across 11 tactics, including:
• Remote monitoring and management tool abuse — AnyDesk, NetSupport, Atera and MeshAgent used for access and ransomware staging
• Execution and obfuscation — encoded PowerShell, script-based payload unpacking, maldoc execution chains, downloads via .NET and BITS
• Credential access — LSASS dumping via renamed ProcDump
• Persistence — Run and ASEP registry keys, Startup folder drops, scheduled tasks from abnormal locations, privileged group membership changes
• Defense evasion — shadow copy deletion, wevtutil log clearing, PowerShell history tampering
• Exploitation — anomalous child processes of Java and the IIS worker process (w3wp.exe), covering Log4Shell-class activity
• Cloud — AWS IAM discovery and enumeration
The hunt packages run against data you already collect: Windows Security Events, Microsoft Defender device events, and AWS CloudTrail.
An active Intel 471 subscription with API access is required. For more information, contact sales@intel471.com.
At a glance
https://catalogartifact.azureedge.net/publicartifacts/intel471inc1641226539011.intel471_threat_intelligence-4c303cd0-0820-4cd0-b500-ef3966901a55/image5_intel471indicators.png
https://catalogartifact.azureedge.net/publicartifacts/intel471inc1641226539011.intel471_threat_intelligence-4c303cd0-0820-4cd0-b500-ef3966901a55/image0_intel471logicapp.png