Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Hunting for security threats is a highly customizable activity that's most effective throughout all stages of threat hunting: proactive, reactive, and post incident. The Defender portal provides hunting tools from Microsoft Defender XDR and Microsoft Sentinel for every stage. These tools are well suited for analysts who are just starting their careers and experienced threat hunters who use advanced hunting methods. Threat hunters of all levels benefit from features that let them share techniques, queries, and findings with their teams.
Hunting tools
The foundation of hunting queries in the Defender portal rests on Kusto Query Language (KQL). KQL is a powerful and flexible language that's optimized for searching through big-data stores in cloud environments. However, crafting complex queries isn't the only way to hunt for threats. Here are some more hunting tools and resources within the Defender portal designed to bring hunting into your reach:
- Microsoft Security Copilot in advanced hunting provides prerelease capabilities that include the Threat Hunting Assistant for conversational hunting and the Query assistant for generating KQL from natural language.
- Guided mode uses a query builder for crafting meaningful hunting queries without knowing KQL or the data schema.
- Get help as you write queries with features like autosuggest, schema tree, and sample queries.
- Content hub provides expert queries to match out-of-the-box solutions in Microsoft Sentinel.
- Microsoft Defender Experts Hunting is a separately sold managed threat hunting service that complements security operations teams that want assistance.
Maximize the full extent of your team's hunting prowess with the following hunting tools in the Defender portal:
| Hunting tool | Description |
|---|---|
| Advanced hunting | View and query data sources available from Defender portal services and share queries with your team. After you onboard a Microsoft Sentinel workspace, use its content, including queries and functions. |
| Microsoft Sentinel hunting | Hunt for security threats in your data sources. Use specialized search and query tools such as hunts and bookmarks. |
| Go hunt | Quickly pivot an investigation to entities found within an incident. |
| Hunts (preview) | An end-to-end, proactive threat hunting process with collaboration features. |
| Bookmarks | Preserve queries and their results, and add notes and contextual observations. In the Defender portal, you can view existing Microsoft Sentinel bookmarks but can't create them. Bookmarks aren't available in Advanced hunting. |
| Hunting with summary rules | Use summary rules to save costs hunting for threats in verbose logs. |
| MITRE ATT&CK map (preview) | When creating a new hunting query, select specific tactics and techniques to apply. |
| Restore historical data | Restore data from archived logs to use in high-performance queries. |
| Search large data sets | Search for specific events in up to one year of data in a table using KQL. |
| Threat analytics | Track emerging threats and review Microsoft threat research and insights. |
| Threat explorer | Hunt for specialized threats related to email. |
Hunting stages
The following table describes how you can make the most of the Defender portal's hunting tools throughout all stages of threat hunting:
| Hunting stage | Hunting tools |
|---|---|
| Proactive - Find the weak areas in your environment before threat actors do. Detect suspicious activity extra early. | - Regularly conduct end-to-end hunts (preview) to proactively seek out undetected threats and malicious behaviors, validate hypotheses, and act on findings by creating new detections, incidents, or threat intelligence. - Use the MITRE ATT&CK map (preview) to identify detection gaps, and then run predefined hunting queries for highlighted techniques. - Insert new threat intelligence into proven queries to tune detections and confirm if a compromise is in process. - Take proactive steps to build and test queries against data from new or updated sources. - Use advanced hunting to find early-stage attacks or threats that don't have alerts. |
| Reactive - Use hunting tools during an active investigation. | - Quickly pivot on incidents with the Go hunt button to search broadly for suspicious entities found during an investigation. - Use threat analytics to investigate emerging threats and assess their potential impact. - Use the prerelease Microsoft Security Copilot capabilities in advanced hunting to investigate threats or generate queries. |
| Post incident - Improve coverage and insights to prevent similar incidents from recurring. | - Turn successful hunting queries into new analytics and detection rules, or refine existing ones. - Restore historical data and search large datasets for specialized hunting as part of full incident investigations. |