{"id":38384,"date":"2020-11-25T19:00:14","date_gmt":"2020-11-25T19:00:14","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=92247"},"modified":"2020-11-25T19:00:14","modified_gmt":"2020-11-25T19:00:14","slug":"go-inside-the-new-azure-defender-for-iot-including-cyberx","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/","title":{"rendered":"Go inside the new Azure Defender for IoT including CyberX"},"content":{"rendered":"<p>In 2020, the move toward digital transformation and <a href=\"https:\/\/www.forbes.com\/sites\/bernardmarr\/2018\/09\/02\/what-is-industry-4-0-heres-a-super-easy-explanation-for-anyone\/?sh=c6795919788a\" target=\"_blank\" rel=\"noopener noreferrer\">Industry 4.0<\/a> took on new urgency with manufacturing and other critical infrastructure sectors under pressure to increase operational efficiency and reduce costs. But the cybersecurity model for operational technology (OT) was already shown to be lacking before the pandemic. A series of major cyberattacks across industries served as a wake-up call that the traditional \u201cair-gapped\u201d model for OT cybersecurity had become outdated in the era of IT\/OT convergence and initiatives such as Smart Manufacturing and Smart Buildings. And the IoT and Industrial Internet of things (IIoT) are only getting bigger. Analysts predict we\u2019ll have billions of IoT devices connected worldwide in a few years, drastically increasing the surface area for attacks.<\/p>\n<p>Company boards and management teams are understandably concerned about increased safety and corporate liability risks as well as the financial impact of crippling downtime posed by IoT\/OT breaches. They\u2019re also concerned about losing sensitive IP such as proprietary formulas and product designs, since manufacturers are eight times more likely to be attacked for cyberespionage than other sectors, according to the 2020 Verizon DBIR.<sup>1<\/sup><\/p>\n<p>In my recent Microsoft Ignite presentation, <a href=\"https:\/\/myignite.microsoft.com\/sessions\/973175b0-2a2d-4b41-99f8-051e42ac575a\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Defender for IoT including CyberX<\/a>, I was joined by Nir Krumer, Principal PM Manager at Microsoft, to examine how the new <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-defender-for-iot\/\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Defender for IoT<\/a> incorporates CyberX\u2019s agentless technology and IoT\/OT-aware behavioral analytics, minimizing those risks by providing IT teams with continuous IoT\/OT visibility into their industrial and critical infrastructure networks. You\u2019re invited to view the <a href=\"https:\/\/myignite.microsoft.com\/sessions\/973175b0-2a2d-4b41-99f8-051e42ac575a\" target=\"_blank\" rel=\"noopener noreferrer\">full presentation<\/a> and review some highlights below.<\/p>\n<h2>IT versus OT<\/h2>\n<p>Unlike information technology (IT) security, OT security is focused on securing physical processes and assets rather than digital assets like containers and SQL databases. Physical assets include devices like turbines, mixing tanks, HVAC systems in smart buildings and data centers, factory-floor machines, and more. In OT, the top focus is always on safety and availability. Availability means that your production facilities must be resilient and keep operating, because that\u2019s where the revenue comes from. However, the biggest difference from IT security is that most chief information security officers (CISOs) and SOC teams today have little or no visibility into their OT risk, because they don\u2019t have the multiple layers of controls and telemetry as we have in IT environments. And OT risk translates directly into business risk.<\/p>\n<p>As recent history shows, attacks on OT are already underway. The <a href=\"https:\/\/www.darkreading.com\/operations\/industrial-safety-systems-in-the-bullseye\/d\/d-id\/1330912\" target=\"_blank\" rel=\"noopener noreferrer\">TRITON attack<\/a> on the safety controllers in a Middle East petrochemical facility was intended to cause major structural damage to the facility and possible loss of life. The attackers got their initial foothold in the IT network but subsequently used living-off-the-land (LOTL) tactics to gain remote access to the OT network, where they deployed their purpose-built malware. As this attack demonstrated, increased connectivity between IT and OT networks gives adversaries new ways of compromising unmanaged OT devices, which historically haven\u2019t supported agents and are typically invisible to IT teams.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-92248 size-full aligncenter\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture1.jpg\" alt=\"Purdue Model traversal in TRITON attack\" width=\"1017\" height=\"570\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture1.jpg 1017w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture1-300x168.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture1-768x430.jpg 768w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture1-687x385.jpg 687w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture1-767x431.jpg 767w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture1-539x303.jpg 539w\" sizes=\"auto, (max-width: 1017px) 100vw, 1017px\"><\/p>\n<p><em>Figure 1: Purdue Model traversal in TRITON attack.<\/em><\/p>\n<h2>How Azure Defender for IoT works for you<\/h2>\n<p>By incorporating agentless technology from Microsoft\u2019s recent acquisition of <a href=\"https:\/\/blogs.microsoft.com\/blog\/2020\/06\/22\/microsoft-acquires-cyberx-to-accelerate-and-secure-customers-iot-deployments\/\" target=\"_blank\" rel=\"noopener noreferrer\">CyberX<\/a>, Azure Defender for IoT enables IT and OT teams to identify critical vulnerabilities and detect threats using IoT\/OT-aware behavioral analytics and machine learning\u2014all without impacting availability or performance.<\/p>\n<p>In our Ignite presentation, we broke down five key capabilities provided by the product\u2019s agentless security for unmanaged IoT\/OT devices:<\/p>\n<ul>\n<li><strong>Asset discovery:<\/strong> Because you cannot protect what you do not know you have, Azure Defender tells you what IoT\/OT devices are in your network and how they\u2019re communicating with each other. Also, if you\u2019re implementing a <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/zero-trust\" target=\"_blank\" rel=\"noopener noreferrer\">Zero Trust policy<\/a>, you need to know how these devices are connected so you can segment them onto their own network and manage granular access to them.<\/li>\n<li><strong>Risk and vulnerability management: <\/strong>Azure Defender helps you identify vulnerabilities such as unauthorized devices, unpatched systems, unauthorized internet connections, and devices with unused open ports\u2014so you can take a prioritized approach to mitigating IoT\/OT risk for your crown jewel assets. These are the critical devices whose compromise would have a major impact on your organization, such as a safety incident, loss of revenue, or theft of sensitive IP.<\/li>\n<li><strong>Continuous IoT threat monitoring and response:<\/strong> Azure Defender continuously monitors the OT network using Layer 7 Deep Packet Inspection (DPI), informing you immediately when there has been unusual or unauthorized behavior, and empowering you to mitigate an attack before it causes a production failure or safety incident. It incorporates a deep understanding of all major industrial protocols (including Modbus, DNP3, Siemens S7, Ethernet\/IP CIP, GE-SRTP, and Yokogawa) and patented, IoT\/OT-aware behavioral analytics to detect threats faster and more accurately, with a far shorter learning period than generic baselining algorithms.<\/li>\n<li><strong>Operational efficiency:<\/strong> When you have malfunctioning or misconfigured equipment, you need to quickly figure out what went wrong. By providing deep visibility into what\u2019s going on in the network\u2014such as a misconfigured engineering workstation that\u2019s constantly scanning the network\u2014you can help your IoT\/OT engineers quickly identify and address the root cause of those issues.<\/li>\n<li><strong>Unified IT\/OT security monitoring and governance:<\/strong> Azure Defender for IoT is deeply integrated with Azure Sentinel and also supports third-party tools such as Splunk, IBM QRadar, and ServiceNow. This helps break down silos that slow communication between IT and OT teams, and creates a common language between them to quickly resolve issues. It also enables you to quickly address attacks that cross IT\/OT boundaries (like TRITON), as well as leverage the workflows and training you spent years building in your security operations center (SOC)\u2014so you can apply them to IoT and OT security as well.<\/li>\n<\/ul>\n<h2>Deployment Architecture<\/h2>\n<p>So, how does this system get deployed? Azure Defender for IoT uses a network sensor to capture a copy of the network traffic through the switch port analyzer (SPAN). It uses a technique called passive monitoring or network traffic analysis (NTA) to identify assets, vulnerabilities, and threats without impacting the performance or reliability of the IoT\/OT network. The solution can be 100 percent on-premises, connected to Azure, or a hybrid of the two (for example, by forwarding alerts to Azure Sentinel).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-92250 size-full aligncenter\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture3.jpg\" alt=\"Azure Defender for IoT uses an on-premises network sensor to capture and analyze all OT traffic. The solution can be deployed on-premises, connected to Azure, or in hybrid environments where the SIEM is cloud-based, as with Azure Sentinel.\" width=\"881\" height=\"506\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture3.jpg 881w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture3-300x172.jpg 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture3-768x441.jpg 768w\" sizes=\"auto, (max-width: 881px) 100vw, 881px\"><\/p>\n<p><em>Figure 2: Azure Defender for IoT uses an on-premises network sensor to capture and analyze all IoT\/OT traffic. The solution can be deployed fully on-premises, or connected to Azure, or in hybrid environments where the SIEM is cloud-based, as with Azure Sentinel.<\/em><\/p>\n<h2>Azure Sentinel integration<\/h2>\n<p>To enable rapid detection and response for attacks that cross IT\/OT boundaries, Azure Defender is deeply integrated with <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-sentinel\/\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Sentinel<\/a>\u2014Microsoft\u2019s cloud-native SIEM\/SOAR platform. As a SaaS-based solution, Azure Sentinel delivers reduced complexity, built-in scalability, lower total cost of ownership (TCO), and continuous threat intelligence and software updates. It also provides built-in IoT\/OT security capabilities, including:<\/p>\n<ul>\n<li><strong>Deep integration with Azure Defender for IoT:<\/strong> Azure Sentinel provides rich contextual information about specialized OT devices and behaviors detected by Azure Defender\u2014enabling your SOC teams to correlate and detect modern kill-chains that move laterally across IT\/OT boundaries.<\/li>\n<li><strong>IoT\/OT-specific SOAR playbooks:<\/strong> Sample playbooks enable automated actions to swiftly remediate IoT\/OT threats.<\/li>\n<li><strong>IoT\/OT-specific threat intelligence:<\/strong> In addition to the trillions of signals collected daily, Azure Sentinel now incorporates IoT\/OT-specific threat intelligence provided by Section 52, our specialized security research team focused on IoT\/OT malware, campaigns, and adversaries.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-92251 size-full aligncenter\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture5.png\" alt width=\"729\" height=\"418\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture5.png 729w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2020\/11\/Picture5-300x172.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\"><\/p>\n<p>You are invited to watch our <a href=\"https:\/\/myignite.microsoft.com\/sessions\/973175b0-2a2d-4b41-99f8-051e42ac575a\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Ignite presentation<\/a> to learn more about Azure Defender for IoT, including a live demo of how deep integration with Azure Sentinel can be used to investigate multistage IT\/OT attacks like TRITON.<\/p>\n<p>Visit the <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-defender-for-iot\/\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Defender for IoT website<\/a> to learn more and try it for free during Public Preview. You can also learn more about Microsoft Security solutions by <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\/solutions\" target=\"_blank\" rel=\"noopener noreferrer\">visiting our&nbsp;website<\/a>. Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noopener noreferrer\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us at&nbsp;<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noopener noreferrer\">@MSFTSecurity<\/a>&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<hr>\n<p><em><sup>1<\/sup> <a href=\"https:\/\/enterprise.verizon.com\/resources\/reports\/2020-data-breach-investigations-report.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">2020 Verizon DBIR<\/a>, pages 36 and 59.<\/em><\/p>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/11\/25\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In 2020, the move toward digital transformation and Industry 4.0 took on new urgency with manufacturing and other critical infrastructure sectors under pressure to increase operational efficiency and reduce costs. But the cybersecurity model for operational technology (OT) was already shown to be lacking before the pandemic. A series of major cyberattacks across industries served&#8230;<br \/>\nThe post Go inside the new Azure Defender for IoT including CyberX appeared first on Microsoft Security. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":38385,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[6426,8909,347,236],"class_list":["post-38384","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-azure-security","tag-azure-sentinel","tag-cybersecurity","tag-iot-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Go inside the new Azure Defender for IoT including CyberX 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Go inside the new Azure Defender for IoT including CyberX 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2020-11-25T19:00:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/go-inside-the-new-azure-defender-for-iot-including-cyberx.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1017\" \/>\n\t<meta property=\"og:image:height\" content=\"570\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Go inside the new Azure Defender for IoT including CyberX\",\"datePublished\":\"2020-11-25T19:00:14+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/\"},\"wordCount\":1350,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx.jpg\",\"keywords\":[\"Azure Security\",\"Azure Sentinel\",\"Cybersecurity\",\"IoT security\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/\",\"name\":\"Go inside the new Azure Defender for IoT including CyberX 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx.jpg\",\"datePublished\":\"2020-11-25T19:00:14+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/11\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx.jpg\",\"width\":1017,\"height\":570},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/go-inside-the-new-azure-defender-for-iot-including-cyberx\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Azure Security\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/azure-security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Go inside the new Azure Defender for IoT including CyberX\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Go inside the new Azure Defender for IoT including CyberX 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/","og_locale":"en_US","og_type":"article","og_title":"Go inside the new Azure Defender for IoT including CyberX 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2020-11-25T19:00:14+00:00","og_image":[{"width":1017,"height":570,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/go-inside-the-new-azure-defender-for-iot-including-cyberx.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Go inside the new Azure Defender for IoT including CyberX","datePublished":"2020-11-25T19:00:14+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/"},"wordCount":1350,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/go-inside-the-new-azure-defender-for-iot-including-cyberx.jpg","keywords":["Azure Security","Azure Sentinel","Cybersecurity","IoT security"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/","url":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/","name":"Go inside the new Azure Defender for IoT including CyberX 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/go-inside-the-new-azure-defender-for-iot-including-cyberx.jpg","datePublished":"2020-11-25T19:00:14+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/go-inside-the-new-azure-defender-for-iot-including-cyberx.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2020\/11\/go-inside-the-new-azure-defender-for-iot-including-cyberx.jpg","width":1017,"height":570},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/go-inside-the-new-azure-defender-for-iot-including-cyberx\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Azure Security","item":"https:\/\/www.threatshub.org\/blog\/tag\/azure-security\/"},{"@type":"ListItem","position":3,"name":"Go inside the new Azure Defender for IoT including CyberX"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/38384","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=38384"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/38384\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/38385"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=38384"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=38384"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=38384"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}