Microsoft has announced a free threat intelligence API designed specifically for small and medium businesses that lack dedicated security operations centers. The service, called Defender Threat Intel Essentials, provides real-time indicators of compromise, vulnerability alerts, and basic threat hunting capabilities through a simple REST API.
The free tier includes up to 10,000 API calls per month, access to Microsoft's global threat intelligence database, and integration guides for popular SIEM platforms including Splunk, Elastic, and open-source alternatives like Wazuh.
Microsoft said the initiative aims to address the growing cybersecurity gap between large enterprises with robust security teams and smaller organizations that are increasingly targeted by sophisticated threat actors.