Microsoft Learn references
KQL Threat Hunting Field Guide
Every reference the book lists, as a link, under the book's own headings. If a page has moved, search Microsoft Learn for its title.
Unified Platform and Hunting Surfaces
- What are unified security operations in the Microsoft Defender portal?
- Microsoft Sentinel in the Microsoft Defender portal
- Connect Microsoft Sentinel to the Microsoft Defender portal
- Hunting in the Microsoft Defender portal
- Proactively hunt for threats with advanced hunting in Microsoft Defender
- Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal
Licensing, Quotas, and Data Coverage
- Choose between guided and advanced modes to hunt in Microsoft Defender XDR
- Quotas and usage parameters (advanced hunting service limits)
- Use the advanced hunting query resource report
- Handle advanced hunting errors
- Extend advanced hunting coverage with the right settings
KQL Foundations and Query Best Practices
- Learn the advanced hunting query language
- Advanced hunting query best practices
- Best practices for Kusto Query Language queries
- Optimize log queries in Azure Monitor
Advanced Hunting Schema Tables
- Understand the advanced hunting schema
- Migrate advanced hunting queries from Microsoft Defender for Endpoint
- DeviceProcessEvents table
- IdentityLogonEvents table
- IdentityDirectoryEvents table
- EmailPostDeliveryEvents table
- UrlClickEvents table
- CloudAppEvents table
Writing, Sharing, and Taking Action on Queries
- Advanced hunting example for Microsoft Defender for Office 365
- Take action on advanced hunting query results
- Microsoft Security Copilot in advanced hunting
Custom Detection Rules
- Create custom detection rules in Microsoft Defender XDR
- Feature comparison: Sentinel analytics rules and Defender custom detections
- Threat detection in Microsoft Sentinel
Sentinel Hunting, Bookmarks, and Hunts
- Threat hunting in Microsoft Sentinel
- Conduct end-to-end proactive threat hunting in Microsoft Sentinel
- Keep track of data during hunting with Microsoft Sentinel (bookmarks)
Entity Graphs, UEBA, and Blast Radius
- Enable User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel
- Advanced threat detection with UEBA in Microsoft Sentinel
- Investigate incidents in the Microsoft Defender portal (blast radius)
- Query the enterprise exposure graph
- make-graph operator
- Schemas and operators overview (Security Exposure Management)
Data Lake, KQL Jobs, Search Jobs, and Summary Rules
- Manage data tiers and retention in Microsoft Sentinel
- KQL jobs, summary rules, and search jobs
- Search for specific events across large datasets in Microsoft Sentinel
- Aggregate Microsoft Sentinel data with summary rules
- Aggregate data in a Log Analytics workspace by using summary rules