hero-background-color-red-orange-gradient
image
https://assets.lumen.com/is/image/Lumen/25-078_Orleman_Announcingthe-preview_HERO?Creativeid=8cff6f55-20e7-4ed4-bf63-6c720d999f64
https://assets.lumen.com/is/image/Lumen/25-078_Orleman_Announcingthe-preview_HERO?Creativeid=8cff6f55-20e7-4ed4-bf63-6c720d999f64
https://assets.lumen.com/is/image/Lumen/25-078_Orleman_Announcingthe-preview_card-hero?Creativeid=
Two people seated across from each other at a table dressed in business attire and engaged in a conversation with a computer monitor between them set against an abstract, multi-colored background.
content
content-col-11

Announcing the preview of Lumen Defender℠ threat feed for Microsoft Sentinel

We’re excited to unveil a new collaboration between Lumen and Microsoft — introducing the Lumen Defender Threat Feed, now available in the Microsoft Security Store as a limited preview. This marks a powerful step forward in delivering advanced threat intelligence to help organizations strengthen their security posture.

For the first time, security teams will be able to seamlessly access curated, high-fidelity network-based threat intelligence from Black Lotus Labs®, directly within Microsoft Sentinel. This integration enables security teams to enrich alerts, pinpoint critical threats and enhance incident response by connecting internal signals to external adversary infrastructure.

Enhancing security with Lumen Defender threat feed

As adversaries grow more sophisticated and increase their reach across sprawling global infrastructure, security teams need visibility into the networks those adversaries use—so they can correlate incidents observed on internal networks and endpoints with the broader infrastructure behind the threat.

Lumen’s approach is to leverage the unparalleled threat research and operational strength of Black Lotus Labs through a new product offer, Lumen Defender Threat Feed for Microsoft Sentinel, to deliver fast, actionable insights directly to Sentinel, Microsoft’s industry-leading SIEM and AI-first platform. We enable Security Operations Center (SOC) analysts and security teams to correlate internal enterprise alerts with external adversary infrastructure, prioritize high-fidelity threats and respond faster with enriched context. Joint customers of Lumen Defender Threat Feed and Microsoft Sentinel can now experience:

The power of collaboration: Lumen and Microsoft

Security teams today are overwhelmed. SOCs are inundated with thousands of alerts daily—many of them low-fidelity, repetitive or lacking actionable context. Analysts can spend hours chasing down signals from endpoints, firewalls and cloud workloads, often without the visibility needed to connect the dots. The result? Alert fatigue, missed threats and reactive defense.

Take a common scenario: an endpoint alert flags a suspicious executable making a callback to an unfamiliar IP address. End-point threat intelligence, powered by deep visibility across millions of endpoints, helps identify the malware behavior, flag the callback and alert the SOC to a potential compromise. This is invaluable—it gives the team a starting point and confirms that something malicious is happening on the device.

But the investigation stalls. The IP has no known reputation, and there’s no clear link to a broader campaign. What the endpoint couldn’t see was that the IP was part of a newly activated command-and-control network spanning multiple geographies—used by an advanced persistent threat (APT) group to coordinate attacks. Without visibility into the infrastructure behind the alert, the SOC is left with fragments, unable to assess risk or respond effectively.

That’s where Lumen comes in.

Black Lotus Labs, the Lumen threat research arm, sees the internet from the outside in. Take the analogy of endpoint intelligence as watching your house from the inside—you’ll know when someone breaks a window or tampers with a lock. Lumen network-derived intelligence, powered by Black Lotus Labs, is like having surveillance on the entire neighborhood. It sees the suspicious vehicles circling the block, the coordinated movement patterns and the infrastructure attackers use before they ever reach your door.

Tying this to the scenario above, Black Lotus Labs can trace that IP to a broader malicious infrastructure, uncover related domains, identify other victims and attribute the activity to a known APT group. Endpoint intelligence sees the threat on the device; Lumen sees the infrastructure behind it. Together, these give security teams the complete picture—connecting internal alerts to external adversary operations, enriching detection and enabling faster, more confident response.

“The most critical threats aren’t always the ones screaming the loudest. By eliminating noise and surfacing hidden adversary infrastructure and infrastructure-level context, we enable SOC teams to respond fast, with greater confidence—and stay ahead of attackers,” said Martin Nystrom, VP Engineering, Black Lotus Labs.

By integrating Lumen Defender Threat Feed directly into Microsoft Sentinel, we’re giving security teams the outside-in visibility they’ve been missing. This partnership allows SOCs to correlate internal alerts with external adversary infrastructure—enriching detection, reducing false positives, and accelerating response.

It’s a meaningful step forward for our shared customers, expanding the operational reach of Black Lotus Labs’ research and making it accessible within the Microsoft Security ecosystem for the first time.

This is what sets the collaboration apart. It’s not just the quality of the data, but the seamless integration and operational value it delivers. Microsoft Sentinel users can now leverage the Lumen Defender Threat Feed to:

Who is Black Lotus Labs?

Black Lotus Labs is the Lumen Threat Research and Operations division—a multidisciplinary team of data scientists, reverse engineers, security engineers and threat analysts who specialize in detecting, tracking and disrupting digital threats worldwide. What sets Black Lotus Labs apart is their unmatched network visibility:

This massive scale allows Black Lotus Labs to map and monitor malicious infrastructure with extraordinary confidence and speed. By seeing more of the world’s internet activity—across botnets, malware, C2 networks, criminal proxies and even nation-state operations—the team can rapidly identify patterns of malicious behavior. Their research is the foundation for advanced detection and machine learning algorithms, which validate IOCs with high fidelity before they can reach Lumen customers.

Explore blogs from Black Lotus Labs, including our latest research on botnet groups.

Get started: Preview now available

A preview of Lumen Defender Threat Feed for Microsoft Sentinel is available now by invitation only via the Microsoft Store.

Contact the Lumen Sales Team to request access to the trial and get started today.

primaryOrange
Request invite
mailto:defenderthreatfeedsales@lumen.com
_blank

1The Center for Applied Internet Data Analysis (CAIDA), AS Rank, January 2025.

This content is provided for informational purposes only and may require additional research and substantiation by the end user. In addition, the information is provided “as is” without any warranty or condition of any kind, either express or implied. Use of this information is at the end user’s own risk. Lumen does not warrant that the information will meet the end user’s requirements or that the implementation or usage of this information will result in the desired outcome of the end user. All third-party company and product or service names referenced in this article are for identification purposes only and do not imply endorsement or affiliation with Lumen. This document represents Lumen products and offerings as of the date of issue. Services not available everywhere. Lumen may change or cancel products and services or substitute similar products and services at its sole discretion without notice. ©2025 Lumen Technologies. All Rights Reserved.

image
https://assets.lumen.com/is/image/Lumen/author-lauren-orleman-image-300x300?Creativeid=14035383-478c-408e-9e6a-e948d4eeedd4
https://assets.lumen.com/is/image/Lumen/author-lauren-orleman-image-300x300?Creativeid=14035383-478c-408e-9e6a-e948d4eeedd4
https://assets.lumen.com/is/image/Lumen/author-lauren-orleman-image-300x300?Creativeid=14035383-478c-408e-9e6a-e948d4eeedd4
Lauren Orleman, senior lead manager of product headshot
content
Author
Lauren Orleman
Lauren Orleman is a dynamic Sr. Product Marketing Manager at Lumen, where she brings her expertise in content strategy and development to the forefront of the company’s Cybersecurity, Voice, Unified Communications & Collaboration, Contact Center, and Managed & Professional Services portfolios. Lauren’s role is pivotal in integrating cross-functional teams to deliver a cohesive marketing message that aligns with the Lumen vision and values. With a Bachelor of Science in Marketing from Providence College School of Business, Lauren combines her academic knowledge with her professional experience to drive innovative marketing strategies and deliver compelling content that resonates with customers and stakeholders alike.
image
https://assets.lumen.com/is/image/Lumen/img-blog-featured-resource-card-bll?Creativeid=844b527d-b24a-4d66-928e-9d6964fc2220
https://assets.lumen.com/is/image/Lumen/img-blog-featured-resource-card-bll?Creativeid=844b527d-b24a-4d66-928e-9d6964fc2220
https://assets.lumen.com/is/image/Lumen/img-blog-featured-resource-card-bll?Creativeid=844b527d-b24a-4d66-928e-9d6964fc2220
Video thumbnail showing abstract blue and white light trails curving upward against a dark background, with small glowing particles scattered throughout. A red circular play button is centered on the image, and a time stamp of 1 minute 52 seconds appears in the bottom-right corner.
content
VIDEO
See how Black Lotus Labs® helps protect your business
link
Watch video
https://players.brightcove.net/1186058296001/ObIoHMsRd_default/index.html?videoId=6341053041112
_self
content
Related products

Defender

DDoS Hyper

Rapid Threat Defense