Cyware has announced a strategic collaboration with Microsoft, focusing on the integration of AI-powered threat intelligence management, automation, and security orchestration.
This partnership aims to assist global enterprises and public sector organisations in operationalising threat intelligence more swiftly and confidently. By merging their products, Cyware and Microsoft offer an integrated threat intelligence workflow with Microsoft Sentinel, smoothing the transition from threat insights to actionable measures.
Expanding partnership for seamless operations
This approach automates threat intelligence processes, from ingestion to action
Building upon their existing partnership, Cyware’s solutions are already accessible through Microsoft's Commercial Marketplace, simplifying procurement for both commercial and government clients. The expanded collaboration aims to deliver a comprehensive solution that modernises security operations.
This approach automates threat intelligence processes, from ingestion to action. Integrating Microsoft Sentinel with Cyware Intel Exchange facilitates a bi-directional threat intelligence exchange, supporting STIX/TAXII-based sharing to enhance indicator validation at scale.
Streamlining threat intelligence
Security teams face challenges in scaling threat intelligence operations due to fragmented data, inconsistent context, and manual tool interactions.
The partnership allows Microsoft Sentinel to acquire actionable intelligence from Cyware, streamlining the investigation and response processes via real-time context sharing. In return, Cyware benefits by receiving intelligence from Microsoft Sentinel for faster action.
AI-driven security enhancements
Anuj Goel, CEO and Co-Founder of Cyware, commented, “This partnership with Microsoft combines Cyware’s AI-powered intelligence operations with Microsoft's security technology to enable quicker, smarter decisions. By integrating with Microsoft Sentinel and offering deployment via Microsoft's Commercial Marketplace, we minimise the purchase-to-value timeline.”
Empowering defenders with intelligence
Erez Einav, Corporate Vice President at Microsoft, stated, “We are committed to providing defenders with a connected, intelligence-driven experience. This partnership enhances the sharing, validation, and automation of threat intelligence within Microsoft Sentinel, streamlining workflows and improving response times.”
The collaboration also integrates Cyware Intel Exchange with Microsoft Defender, facilitating the enrichment and automated analysis of Defender Threat Intelligence feeds, thus expediting triage and investigation activities.
Inclusion in MISA and future collaborations
This partnership announcement follows Cyware’s recent inclusion in the Microsoft Intelligent Security Association (MISA) and its involvement as an initial launch partner of Microsoft Security Copilot.
The alliance strengthens ongoing integrations between Cyware Intel Exchange, Microsoft Sentinel, and Microsoft Defender, supporting Azure-hosted deployments for customers standardising on Microsoft.
Cyware, a pioneer in AI-powered threat intelligence management, automation, and security orchestration, announced a strategic partnership with Microsoft built on deep product integrations to help global enterprises and public sector organisations operationalise threat intelligence with greater speed, ease and confidence.
The partnership delivers a uniquely integrated threat intelligence workflow across Cyware and Microsoft Sentinel, giving customers a faster path from threat insights to action.
Expanding partnership
As a Microsoft partner, Cyware’s solutions are already available in the Microsoft Commercial Marketplace, simplifying procurement for commercial and government buyers. The companies are now expanding on their partnership to deliver an end-to-end solution that modernises security operations automating threat intelligence ingestion, enrichment, and actioning.
The deep integration between Microsoft Sentinel and Cyware Intel Exchange enables bi-directional threat intelligence exchange, including support for STIX/TAXII-based threat intelligence sharing to validate indicators at scale for mutual customers.
Operationalising threat intelligence
Many security teams still struggle to operationalise threat intelligence at scale due to siloed data, inconsistent context and validation, and manual handoffs between tools.
With this collaboration, Microsoft Sentinel can ingest actionable threat intelligence from Cyware, while Cyware can receive intelligence from Microsoft Sentinel to drive faster investigations and response with real-time context sharing and actioning.
AI-powered threat intelligence operations
“This partnership with Microsoft brings together Cyware’s strength in AI-powered threat intelligence operations and Microsoft’s security technology to help customers make smarter, faster decisions,” said Anuj Goel, CEO and Co-Founder, Cyware.
“By meeting defenders directly in Microsoft Sentinel, and making Cyware deployable through Microsoft Commercial Marketplace we are reducing friction from purchase to value while giving security teams enriched, high-fidelity intelligence they can act on immediately.”
Intelligence-driven experience
“We’re focused on empowering every defender with a more connected, intelligence-driven experience,” said Erez Einav, Corporate Vice President, Sentinel and Defender XDR at Microsoft, adding “This partnership with Cyware extends how threat intelligence is shared, validated, and automated across Microsoft Sentinel, helping customers streamline workflows, strengthen detection quality, and accelerate response.”
In addition to the Microsoft Sentinel integration, Cyware Intel Exchange also integrates with Microsoft Defender, enabling Defender Threat Intelligence feeds to flow into Cyware for enrichment and automated indicator searches against Microsoft Defender data, speeding triage and investigation.
Cyware’s inclusion in MISA
This announcement also builds on Cyware’s recent inclusion in the Microsoft Intelligent Security Association (MISA) and continued momentum with Microsoft Security Copilot, where Cyware participated as one of the inaugural Copilot launch partners.
The collaboration strengthens ongoing integrations between Cyware Intel Exchange, Microsoft Sentinel, and Microsoft Defender and supports Azure-hosted deployment options for customers standardising on Microsoft.