Sentinel analytics rule types: NRT vs Fusion vs TI vs ML Behavior

Verdict: NRT runs once a minute. Fusion and Threat Intelligence Analytics use hidden logic you cannot edit. TI matches indicators against CEF, Syslog and DNS. ML Behavior Analytics flags anomalous SSH and RDP logins.

CriterionScheduledNRTFusion (multistage)Threat Intelligence AnalyticsML Behavior Analytics
CadenceAnalyst-set frequencyOnce every minuteContinuous correlationContinuous matchingModel-driven
Logic customisableYes, analyst KQLYes, analyst KQLNo, hiddenNo, hiddenNo, hidden
Instances per workspaceManyManyOne onlyOneOne
What it detectsAny KQL conditionSame as scheduled, fasterCorrelated multistage attacksIP, domain and URL indicators in CEF, Syslog, DNSAnomalous SSH and RDP logins by IP, geo and history

Rules

Traps