{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/",
        "slug": "dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/"
        },
        "title": "Separate expired threat indicators from current action candidates in Defender threat analytics",
        "summary": "Why does the preview Indicators tab retain expired IOCs?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:09+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 244,
        "potentially_affected": "Verified tenants using the preview Indicators tab in Microsoft Defender threat analytics.",
        "dse_recommendation": "Preserve an indicator's historical investigation purpose separately from any proposed current blocking decision.",
        "primary_source": {
            "name": "Threat analytics in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-xdr/threat-analytics",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>The preview Indicators tab in Defender threat analytics lists indicators associated with a tracked threat. Microsoft researchers update the list as new evidence appears, but it also retains expired indicators to support investigation of past threats. Access to the tab requires tenant verification. <a href=\"https://learn.microsoft.com/en-us/defender-xdr/threat-analytics\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this distinction when taking indicators from a threat report into an investigation or action review. Presence in that retained list should not be presented as an assertion that every entry has the same current operational status.</p>\n<h2>DSE recommendation</h2>\n<p>Preserve an indicator&#8217;s historical investigation purpose separately from any proposed current blocking decision. Record the associated report, the indicator&#8217;s available status and the period the analyst intends to examine. Keep historical hunting inputs separate from the list awaiting present-day enforcement approval. Do not automatically promote every retained entry into a blocking configuration simply because it appears beside newer intelligence.</p>\n<h2>Verification</h2>\n<p>Inspect the selected indicator and its report context before running a bounded historical query. Compare any result with the relevant observation time and document what the match actually establishes. If a current action is proposed, obtain the additional current context and approval needed for that decision instead of recycling the historical match as sufficient justification. Retain nonmatches and access limitations honestly; neither an expired entry nor an empty search is evidence that the environment was never affected. No hunt result or enforcement change is claimed here.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-xdr/threat-analytics\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Threat analytics Indicators preview</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nThe preview Indicators tab in Defender threat analytics lists indicators associated with a tracked threat. Microsoft researchers update the list as new evidence appears, but it also retains expired indicators to support investigation of past threats. Access to the tab requires tenant verification. Microsoft Learn.\nApplicability\nUse this distinction when taking indicators from a threat report into an investigation or action review. Presence in that retained list should not be presented as an assertion that every entry has the same current operational status.\nDSE recommendation\nPreserve an indicator’s historical investigation purpose separately from any proposed current blocking decision. Record the associated report, the indicator’s available status and the period the analyst intends to examine. Keep historical hunting inputs separate from the list awaiting present-day enforcement approval. Do not automatically promote every retained entry into a blocking configuration simply because it appears beside newer intelligence.\nVerification\nInspect the selected indicator and its report context before running a bounded historical query. Compare any result with the relevant observation time and document what the match actually establishes. If a current action is proposed, obtain the additional current context and approval needed for that decision instead of recycling the historical match as sufficient justification. Retain nonmatches and access limitations honestly; neither an expired entry nor an empty search is evidence that the environment was never affected. No hunt result or enforcement change is claimed here.\nOfficial references\nMicrosoft Learn: Threat analytics Indicators preview. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nThe preview Indicators tab in Defender threat analytics lists indicators associated with a tracked threat. Microsoft researchers update the list as new evidence appears, but it also retains expired indicators to support investigation of past threats. Access to the tab requires tenant verification. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-xdr/threat-analytics).\n\n## Applicability\n\nUse this distinction when taking indicators from a threat report into an investigation or action review. Presence in that retained list should not be presented as an assertion that every entry has the same current operational status.\n\n## DSE recommendation\n\nPreserve an indicator’s historical investigation purpose separately from any proposed current blocking decision. Record the associated report, the indicator’s available status and the period the analyst intends to examine. Keep historical hunting inputs separate from the list awaiting present-day enforcement approval. Do not automatically promote every retained entry into a blocking configuration simply because it appears beside newer intelligence.\n\n## Verification\n\nInspect the selected indicator and its report context before running a bounded historical query. Compare any result with the relevant observation time and document what the match actually establishes. If a current action is proposed, obtain the additional current context and approval needed for that decision instead of recycling the historical match as sufficient justification. Retain nonmatches and access limitations honestly; neither an expired entry nor an empty search is evidence that the environment was never affected. No hunt result or enforcement change is claimed here.\n\n## Official references\n\n[Microsoft Learn: Threat analytics Indicators preview](https://learn.microsoft.com/en-us/defender-xdr/threat-analytics). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate expired threat indicators from current action candidates in Defender threat analytics",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/",
                "headline": "Separate expired threat indicators from current action candidates in Defender threat analytics",
                "description": "Why does the preview Indicators tab retain expired IOCs?",
                "abstract": "Why does the preview Indicators tab retain expired IOCs?",
                "articleBody": "Source facts\nThe preview Indicators tab in Defender threat analytics lists indicators associated with a tracked threat. Microsoft researchers update the list as new evidence appears, but it also retains expired indicators to support investigation of past threats. Access to the tab requires tenant verification. Microsoft Learn.\nApplicability\nUse this distinction when taking indicators from a threat report into an investigation or action review. Presence in that retained list should not be presented as an assertion that every entry has the same current operational status.\nDSE recommendation\nPreserve an indicator’s historical investigation purpose separately from any proposed current blocking decision. Record the associated report, the indicator’s available status and the period the analyst intends to examine. Keep historical hunting inputs separate from the list awaiting present-day enforcement approval. Do not automatically promote every retained entry into a blocking configuration simply because it appears beside newer intelligence.\nVerification\nInspect the selected indicator and its report context before running a bounded historical query. Compare any result with the relevant observation time and document what the match actually establishes. If a current action is proposed, obtain the additional current context and approval needed for that decision instead of recycling the historical match as sufficient justification. Retain nonmatches and access limitations honestly; neither an expired entry nor an empty search is evidence that the environment was never affected. No hunt result or enforcement change is claimed here.\nOfficial references\nMicrosoft Learn: Threat analytics Indicators preview. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:22:09+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-587-separate-expired-threat-indicators-from-current-action-candidates-in-defender/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate expired threat indicators from current action candidates in Defender threat analytics"
                },
                "articleSection": [
                    "Cybersecurity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    }
                ],
                "wordCount": 244,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Threat analytics in Microsoft Defender - Microsoft Defender XDR | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-xdr/threat-analytics"
                }
            }
        ]
    }
}