Cyware has announced a strategic alliance with Microsoft, focusing on AI-based threat intelligence management and security orchestrations. This partnership aims to enhance global enterprises and public sector entities' ability to operationalize threat intelligence swiftly and efficiently.
The integration between Cyware and Microsoft Sentinel is designed to streamline the process from threat insight to actionable response.
Expanding Partnership with Microsoft
Already available in the Microsoft Commercial Marketplace, Cyware’s solutions are easily accessible for commercial and government entities. This collaboration with Microsoft extends their existing relationship to deliver a comprehensive solution. The partnership aims to modernize security operations by automating the processes of threat intelligence ingestion, enrichment, and action.
Key to this collaboration is the deep integration between Microsoft Sentinel and Cyware Intel Exchange, enabling bi-directional threat intelligence exchange. This includes provisions for STIX/TAXII-based sharing to enhance the validation of indicators for mutual customers, improving operational efficiency.
Operationalizing Threat Intelligence at Scale
Security teams often face challenges in operationalizing threat intelligence due to fragmented data
Security teams often face challenges in operationalizing threat intelligence due to fragmented data, lack of consistent context, and manual processes.
Through this partnership, Microsoft Sentinel can now ingest actionable threat intelligence from Cyware, while Cyware can reciprocate by assimilating intelligence from Microsoft Sentinel. This real-time context sharing is designed to expedite investigations and responses.
AI-Powered Threat Intelligence Operations
Anuj Goel, CEO and Co-Founder of Cyware, stated, “This partnership with Microsoft brings together Cyware’s strength in AI-powered threat intelligence operations and Microsoft’s security technology to help customers make smarter, faster decisions.”
The collaboration is aimed at reducing friction in the procurement process and offering security teams enriched, actionable intelligence.
Intelligence-Driven Experience Across Platforms
Erez Einav, Corporate Vice President at Microsoft, commented, “We’re focused on empowering every defender with a more connected, intelligence-driven experience.”
The partnership is set to enhance how threat intelligence is shared, validated, and automated across Microsoft Sentinel, thus improving workflow efficiency, detection quality, and response time.
Beyond its integration with Microsoft Sentinel, Cyware Intel Exchange also connects with Microsoft Defender. This allows Defender Threat Intelligence feeds to be enriched and searched automatically within Cyware, expediting triage and investigations.
Cyware’s Role in MISA and Beyond
This partnership builds upon Cyware’s recent inclusion in the Microsoft Intelligent Security Association (MISA) and its involvement with the Microsoft Security Copilot as one of the initial launch partners.
The collaboration continues to strengthen the integration between Cyware Intel Exchange, Microsoft Sentinel, and Microsoft Defender, while also supporting Azure-hosted deployment options for customers choosing Microsoft solutions.
Cyware, a pioneer in AI-powered threat intelligence management, automation, and security orchestration, announced a strategic partnership with Microsoft built on deep product integrations to help global enterprises and public sector organizations operationalize threat intelligence with greater speed, ease and confidence.
The partnership delivers a uniquely integrated threat intelligence workflow across Cyware and Microsoft Sentinel, giving customers a faster path from threat insights to action.
Expanding partnership
As a Microsoft partner, Cyware’s solutions are already available in the Microsoft Commercial Marketplace, simplifying procurement for commercial and government buyers. The companies are now expanding on their partnership to deliver an end-to-end solution that modernizes security operations automating threat intelligence ingestion, enrichment, and actioning.
The deep integration between Microsoft Sentinel and Cyware Intel Exchange enables bi-directional threat intelligence exchange, including support for STIX/TAXII-based threat intelligence sharing to validate indicators at scale for mutual customers.
Operationalizing threat intelligence
Many security teams still struggle to operationalize threat intelligence at scale due to siloed data, inconsistent context and validation, and manual handoffs between tools.
With this collaboration, Microsoft Sentinel can ingest actionable threat intelligence from Cyware, while Cyware can receive intelligence from Microsoft Sentinel to drive faster investigations and response with real-time context sharing and actioning.
AI-powered threat intelligence operations
“This partnership with Microsoft brings together Cyware’s strength in AI-powered threat intelligence operations and Microsoft’s security technology to help customers make smarter, faster decisions,” said Anuj Goel, CEO and Co-Founder, Cyware.
“By meeting defenders directly in Microsoft Sentinel, and making Cyware deployable through Microsoft Commercial Marketplace we are reducing friction from purchase to value while giving security teams enriched, high-fidelity intelligence they can act on immediately.”
Intelligence-driven experience
“We’re focused on empowering every defender with a more connected, intelligence-driven experience,” said Erez Einav, Corporate Vice President, Sentinel and Defender XDR at Microsoft, adding “This partnership with Cyware extends how threat intelligence is shared, validated, and automated across Microsoft Sentinel, helping customers streamline workflows, strengthen detection quality, and accelerate response.”
In addition to the Microsoft Sentinel integration, Cyware Intel Exchange also integrates with Microsoft Defender, enabling Defender Threat Intelligence feeds to flow into Cyware for enrichment and automated indicator searches against Microsoft Defender data, speeding triage and investigation.
Cyware’s inclusion in MISA
This announcement also builds on Cyware’s recent inclusion in the Microsoft Intelligent Security Association (MISA) and continued momentum with Microsoft Security Copilot, where Cyware participated as one of the inaugural Copilot launch partners.
The collaboration strengthens ongoing integrations between Cyware Intel Exchange, Microsoft Sentinel, and Microsoft Defender and supports Azure-hosted deployment options for customers standardizing on Microsoft.