{"id":36342,"date":"2020-07-29T16:30:03","date_gmt":"2020-07-29T16:30:03","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=91635"},"modified":"2020-07-29T16:30:03","modified_gmt":"2020-07-29T16:30:03","slug":"inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/","title":{"rendered":"Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics"},"content":{"rendered":"<p>In theory, a cyberattack can be disrupted at every phase of the attack chain. In reality, however, defense stack boundaries should overlap in order to be effective. When a threat comes via email, for example, even with good security solutions in place, organizations must assume that the threat may slip past email defenses, reach the target recipient, and further compromise endpoints and identities. While defenses on endpoints and identities could successfully tackle the attack in isolation, coordinating signals across protection components significantly increases the ability of these solutions to block and mitigate.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/business\/threat-protection\/integrated-threat-protection\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Threat Protection<\/a> takes this approach and delivers coordinated defense that binds together multiple solutions in the Microsoft 365 security portfolio. Microsoft Threat Protection continuously and seamlessly scours endpoints, email and docs, cloud app, and identity activities for suspicious signals. Through deep correlation logic, Microsoft Threat Protection automatically finds links between related signals across domains. It connects related existing alerts and generates additional alerts where suspicious events that could otherwise be missed can be detected. We call these correlated entities <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/07\/09\/inside-microsoft-threat-protection-correlating-and-consolidating-attacks-into-incidents\/\" target=\"_blank\" rel=\"noopener noreferrer\">incidents<\/a>.<\/p>\n<h3>How Microsoft Threat Protection\u2019s advanced correlation make SOC analysts\u2019 work easier and more efficient<\/h3>\n<p>Microsoft Threat Protection\u2019s incident creation logic combines AI technology and our security experts\u2019 collective domain knowledge, and builds on broad optics to provide comprehensive coverage. These correlations align with the MITRE ATT&amp;CK framework over a unified schema of attack entities, enabling Microsoft Threat Protection to automatically connect the dots between seemingly unrelated signals.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/07\/09\/inside-microsoft-threat-protection-correlating-and-consolidating-attacks-into-incidents\/\" target=\"_blank\" rel=\"noopener noreferrer\">Incidents<\/a> ensure that elements otherwise spread across various portals and queues are presented in a single coherent view, helping security operations centers (SOC) in important ways. First, they reduce the SOC\u2019s workload: incidents automatically collect and correlate isolated alerts and other related security events, so analysts have fewer, more comprehensive work items in their queue. Second, SOC analysts can analyze related alerts, affected assets, and other evidence together, reducing the need for manual correlation and making it easier and faster to understand the complete attack story and take informed actions.<\/p>\n<h3>Attack sprawl illustrated<\/h3>\n<p>The level of sophistication of today\u2019s threats, including <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/06\/18\/inside-microsoft-threat-protection-mapping-attack-chains-from-cloud-to-endpoint\/\" target=\"_blank\" rel=\"noopener noreferrer\">nation-state level attacks<\/a> and <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/03\/05\/human-operated-ransomware-attacks-a-preventable-disaster\/\" target=\"_blank\" rel=\"noopener noreferrer\">human operated ransomware<\/a>, highlight why coordinated defense is critical in ensuring that organizations are protected.<\/p>\n<p>To illustrate how Microsoft Threat Protection protects against such sophisticated attacks, we asked our security research team to simulate an end-to-end attack chain across multiple domains, based on techniques we observed in actual investigations.<\/p>\n<p>Their attack starts with a spear-phishing email targeting a specific user. The email contains a link that, when clicked, leads to the download of a malicious .lnk file that stages the Meterpreter payload. With their malicious code running on the target device, the attackers perform reconnaissance to understand which users have signed into the device and which other devices these users have access to. For example, in this case, they find the credentials of an IT helpdesk team member. Impersonating this IT helpdesk team member via overpass-the-hash, the attackers are able to move laterally to a second device.<\/p>\n<p>On the second device, they steal the user\u2019s web credentials, which they use to remotely access the user\u2019s cloud apps like OneDrive or SharePoint. This allows the attackers to insert a malicious macro into an existing online Word document, which they then deploy in a lateral phishing attack by distributing links to the malicious document to other users in the organization.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-91636\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig1-attack-chain-overpass-the-hash-spear-phishing-lateral-movement.png\" alt=\"Diagram showing an attack chain involving attack sprawl and techniques like overpass-the-hash\" width=\"1730\" height=\"821\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig1-attack-chain-overpass-the-hash-spear-phishing-lateral-movement.png 1730w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig1-attack-chain-overpass-the-hash-spear-phishing-lateral-movement-300x142.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig1-attack-chain-overpass-the-hash-spear-phishing-lateral-movement-1024x486.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig1-attack-chain-overpass-the-hash-spear-phishing-lateral-movement-768x364.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig1-attack-chain-overpass-the-hash-spear-phishing-lateral-movement-1536x729.png 1536w\" sizes=\"auto, (max-width: 1730px) 100vw, 1730px\"><\/p>\n<p><em>Figure 1. Our attack case scenario showing the initial access through spear-phishing and lateral movement through overpass-the-hash attack<\/em><\/p>\n<p>When we ran this attack in our simulation environment, Microsoft Threat Protection was able to track attacker activities as they accessed the target organization, established foothold, and moved across the network. Then, invoking advanced correlation, Microsoft Threat Protection automatically collected all signals, alerts, and relevant entities into a single comprehensive incident representing the whole attack:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-91637\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig2-microsoft-threat-protection-incident.png\" alt=\"Screenshot of the incidents view in Microsoft security center\" width=\"886\" height=\"514\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig2-microsoft-threat-protection-incident.png 886w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig2-microsoft-threat-protection-incident-300x174.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig2-microsoft-threat-protection-incident-768x446.png 768w\" sizes=\"auto, (max-width: 886px) 100vw, 886px\"><\/p>\n<p><em>Figure 2. Incident showing the full attack chain and affected entities<\/em><\/p>\n<h3>Initial access: Correlating email, identity, and endpoint signals<\/h3>\n<p>Let\u2019s look behind the scenes to understand how Microsoft Threat Protection connects the dots in such an attack.<\/p>\n<p>When the target of the initial spear-phishing email clicks the URL in the email, a malicious .lnk file is downloaded and run on the device. In such a scenario, Office 365 Advanced Threat Protection (ATP) flags both the email and the URL as malicious and raises an alert. Normally, SOC analysts would analyze this alert, extract attacker indicators such as the malicious URL, manually search for all devices where this malicious URL was clicked, then take remediation actions on those devices.<\/p>\n<p>Microsoft Threat Protection automates this process and saves time. The intelligence behind Microsoft Threat Protection correlations combines Office 365 ATP signals, Microsoft Defender ATP events, and Azure Active Directory (Azure AD) identity data to find the relevant malicious URL click activity on affected devices, even before SOC analysts starts looking at the alert. The automatic correlation of email, identity, and endpoint signals across on-premises and cloud entities raises the alert \u201cSuspicious URL clicked\u201d. Through this correlation-driven alert, Microsoft Threat Protection helps the SOC to expand their understanding of the attack using all relevant pieces of evidence and automate the search for compromised devices.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-91638\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig3-suspicious-url-clicked.png\" alt=\"Screenshot of Microsoft security center showing list of alerts and highlighting the correlation-driven alert &quot;Suspicious URL clicked&quot;\" width=\"1442\" height=\"558\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig3-suspicious-url-clicked.png 1442w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig3-suspicious-url-clicked-300x116.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig3-suspicious-url-clicked-1024x396.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig3-suspicious-url-clicked-768x297.png 768w\" sizes=\"auto, (max-width: 1442px) 100vw, 1442px\"><\/p>\n<p><em>Figure 3. Microsoft Threat Protection correlation-driven alert \u201cSuspicious URL clicked\u201d<\/em><\/p>\n<h3>Lateral movement: Correlating overpass-the-hash attack on one device and suspicious sign-in on another<\/h3>\n<p>So we\u2019ve seen how automatic correlation allows Microsoft Threat Protection to uncover attacker activity related to initial access. The same capability exposes the next stages in the attack chain: credential theft and lateral movement.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-91639\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig4-correlation-driven-alerts-cross-domain-signals.png\" alt=\"Diagram showing an attack chain and showing correlation of cross-domain signals\" width=\"1730\" height=\"821\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig4-correlation-driven-alerts-cross-domain-signals.png 1730w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig4-correlation-driven-alerts-cross-domain-signals-300x142.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig4-correlation-driven-alerts-cross-domain-signals-1024x486.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig4-correlation-driven-alerts-cross-domain-signals-768x364.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig4-correlation-driven-alerts-cross-domain-signals-1536x729.png 1536w\" sizes=\"auto, (max-width: 1730px) 100vw, 1730px\"><\/p>\n<p><em>Figure 4. Attack scenario showing alerts raised by correlation of cross-domain signals<\/em><\/p>\n<p>In the next stage, the attackers use the overpass-the-hash method, a well-known impersonation technique. They control one device in the network where a domain user, like the IT helpdesk team member, is currently signed in. They then harvest NTLM credentials stored on the device to obtain a Kerberos ticket on the user\u2019s behalf. The Kerberos ticket is a valid ticket that\u2019s encrypted with the credentials of the domain user, allowing the attackers to pretend to be that user and access all resources that the user can access. Once attackers obtain credentials for a user with high privileges, they use the stolen credentials to sign in to other devices and move laterally.<\/p>\n<p>In such cases, Azure ATP raises an alert on the suspicious Kerberos ticket, pointing to a potential overpass-the-hash attack. What would SOC analysts do at this point when investigating an overpass-the-hash alert? They would probably start enumerating all the users who signed in to the compromised device. They would also enumerate all other sign-ins for these users and further activities propagating to other devices in the network, all while mentally building an attack graph.<\/p>\n<p>Saving precious time and eliminating manual work, Microsoft Threat Protection determines that the lateral movement activity is related to the earlier initial access. As a result, Microsoft Threat Protection correlates this activity, as well as users and devices involved, into the same incident, exposing other related activities and surfacing them as additional alerts in the same incident.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-91640\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig5-overpass-the-hash.png\" alt=\"Screenshot of Microsoft security center showing list of alerts and highlighting the correlation-driven alert &quot;Successful logon using potentially stolen credentials&quot;\" width=\"1468\" height=\"251\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig5-overpass-the-hash.png 1468w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig5-overpass-the-hash-300x51.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig5-overpass-the-hash-1024x175.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig5-overpass-the-hash-768x131.png 768w\" sizes=\"auto, (max-width: 1468px) 100vw, 1468px\"><\/p>\n<p><em>Figure 5. Correlating the overpass-the-hash alert<\/em><\/p>\n<p>Microsoft Threat Protection also finds related sign-in events following the overpass-the-hash attack to trace the footprint of the impersonated user and surfaces alerts for malicious sign-ins made by the attacker. This allows Microsoft Threat Protection to elevate a series of raw sign-in events (which, when considered on their own, may lack context for detection) to alerts. The correlation-driven alert \u201cSuccessful logon using potentially stolen credentials\u201d instantly flags the compromised endpoints and pinpoints the start of the malicious activity in the timeline.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-91641\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig6-correlation-driven-alert-start-of-attack-1024x301.png\" alt=\"Screenshot of Microsoft security center showing correlation-driven alerts that determine that start of the attack\" width=\"1024\" height=\"301\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig6-correlation-driven-alert-start-of-attack-1024x301.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig6-correlation-driven-alert-start-of-attack-300x88.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig6-correlation-driven-alert-start-of-attack-768x226.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig6-correlation-driven-alert-start-of-attack.png 1119w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><\/p>\n<p><em>Figure 6. Correlation-driven alert can help determine the start of the attack<\/em><\/p>\n<h3>Lateral phishing: Correlating email, cloud, and device data<\/h3>\n<p>Using the breadth and depth of information available from the incident, SOC analysts can further expand their investigation. The <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/microsoft-threat-protection\/pivot-fast-and-investigate-freely-with-go-hunt-amp-other\/ba-p\/1535768\">Go hunt<\/a> action allows SOC analysts to run an exhaustive, predefined query to hunt for relevant or similar threats and malicious activities from endpoints to the cloud, whether issued from inside the network or outside organizational boundaries.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-91642\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig7-go-hunt.png\" alt=\"Screenshot of Microsoft security center showing the Go hunt action\" width=\"904\" height=\"195\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig7-go-hunt.png 904w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig7-go-hunt-300x65.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig7-go-hunt-768x166.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig7-go-hunt-900x195.png 900w\" sizes=\"auto, (max-width: 904px) 100vw, 904px\"><\/p>\n<p><em>Figure 7. Generating a hunting query with a single click<\/em><\/p>\n<p><em>&nbsp;<\/em>In this attack scenario, the query that Go hunt auto-generates instantly reveals suspicious OneDrive activity: while the user is operating from Great Britain, somebody from Sweden with the same account name seems to have downloaded a .docx file and replaced it with a similar file with .doc extension, indicating the insertion of the malicious macro.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-91643 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig8-go-hunt-user.png\" alt=\"Screenshot of Microsoft security center showing results of the Go hunt query, which reveals additional suspicious acitivity\" width=\"1576\" height=\"313\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig8-go-hunt-user.png 1576w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig8-go-hunt-user-300x60.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig8-go-hunt-user-1024x203.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig8-go-hunt-user-768x153.png 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig8-go-hunt-user-1536x305.png 1536w\" sizes=\"auto, (max-width: 1576px) 100vw, 1576px\"><\/p>\n<p><em>Figure&nbsp; 8. \u201cGo hunt\u201d on the compromised user reveals suspicious activity<\/em><\/p>\n<p>SOCs can further follow the propagation of the replaced file using an additional hunting query that combines email, OneDrive, and device data to find more affected users and devices, allowing SOC analysts to assess if additional compromise occurred and to take remediation actions. In our next blog post, we\u2019ll provide more details about the investigation and hunting aspects of this scenario.<\/p>\n<h3>Conclusion: Connecting the dots and enriching incidents with more signals that tell the story<\/h3>\n<p>In this blog we demonstrated <a href=\"https:\/\/www.microsoft.com\/security\/business\/threat-protection\/integrated-threat-protection\">Microsoft Threat Protection<\/a>\u2019s unique ability to correlate signals across email and docs, devices, identities, and cloud apps, and present attack evidence in a unified form. <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/07\/09\/inside-microsoft-threat-protection-correlating-and-consolidating-attacks-into-incidents\/\">Incidents<\/a> significantly improve SOC efficiency by eliminating the need to use different portals and manually finding and connecting events, as well as enabling investigation and comprehensive response to attacks. The incident view shows alerts, affected entities, and related activities from across Microsoft 365 security solutions in a unified view.<\/p>\n<p>Automatic correlations enrich incidents by consolidating relevant events and raising new alerts on malicious activities that couldn\u2019t be flagged by any individual product on its own. These correlations paint a seamless attack story across perimeters by building an attack graph that SOC analysts can follow, starting with the earliest initial access.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-91644\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig9-automatic-correlations-across-domains.png\" alt=\"Diagram showing automatic correlation of signals and alerts across domains\" width=\"1372\" height=\"747\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig9-automatic-correlations-across-domains.png 1372w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig9-automatic-correlations-across-domains-300x163.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig9-automatic-correlations-across-domains-1024x558.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/07\/fig9-automatic-correlations-across-domains-768x418.png 768w\" sizes=\"auto, (max-width: 1372px) 100vw, 1372px\"><\/p>\n<p><em>Figure 9. Automatic correlation across domains<\/em><\/p>\n<p>Microsoft Threat Protection harnesses the power of Microsoft 365 security products to deliver unparalleled coordinated defense that detects, correlates, blocks, remediates, and prevents attacks across an organization\u2019s Microsoft 365 environment. Existing Microsoft 365 <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/mtp\/prerequisites?view=o365-worldwide\" target=\"_blank\" rel=\"noopener noreferrer\">licenses<\/a> provide access to Microsoft Threat Protection features in Microsoft 365 security center without additional cost. To start using Microsoft Threat Protection, go to <a href=\"https:\/\/security.microsoft.com\" target=\"_blank\" rel=\"noopener noreferrer\">security.microsoft.com<\/a>.<\/p>\n<p>Learn how Microsoft Threat Protection can help your organization to <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/threat-protection\/integrated-threat-protection\" target=\"_blank\" rel=\"noopener noreferrer\">stop attacks with coordinated defense<\/a>. Read these blog posts in the Inside Microsoft Threat Protection series:<\/p>\n<p><strong><em>Stefan Sellmer, Tali Ash, Tal Maor<\/em><\/strong><\/p>\n<p><em>Microsoft Threat Protection Team<\/em><\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/07\/29\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Through deep correlation logic, Microsoft Threat Protection automatically finds links between related signals across domains. It connects related existing alerts and generates additional alerts where suspicious events that could otherwise be missed can be detected.<br \/>\nThe post Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics appeared first on Microsoft Security. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":36343,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[347,7221,4952],"class_list":["post-36342","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-cybersecurity","tag-microsoft-security-intelligence","tag-microsoft-threat-protection"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-07-29T16:30:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1730\" \/>\n\t<meta property=\"og:image:height\" content=\"821\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics\",\"datePublished\":\"2020-07-29T16:30:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/\"},\"wordCount\":1722,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics.png\",\"keywords\":[\"Cybersecurity\",\"Microsoft security intelligence\",\"Microsoft Threat Protection\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/\",\"name\":\"Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics.png\",\"datePublished\":\"2020-07-29T16:30:03+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/07\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics.png\",\"width\":1730,\"height\":821},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/cybersecurity\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/","og_locale":"en_US","og_type":"article","og_title":"Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-07-29T16:30:03+00:00","og_image":[{"width":1730,"height":821,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics","datePublished":"2020-07-29T16:30:03+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/"},"wordCount":1722,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics.png","keywords":["Cybersecurity","Microsoft security intelligence","Microsoft Threat Protection"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/","url":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/","name":"Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics.png","datePublished":"2020-07-29T16:30:03+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/07\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics.png","width":1730,"height":821},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/inside-microsoft-threat-protection-solving-cross-domain-security-incidents-through-the-power-of-correlation-analytics\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity","item":"https:\/\/www.threatshub.org\/blog\/tag\/cybersecurity\/"},{"@type":"ListItem","position":3,"name":"Inside Microsoft Threat Protection: Solving cross-domain security incidents through the power of correlation analytics"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/36342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=36342"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/36342\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/36343"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=36342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=36342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=36342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}