Threat-hunting feature of the Microsoft Defender portal that runs KQL over 30 days of raw Defender XDR data, plus onboarded Sentinel data, and supports custom detections. It finds activity after it happens rather than blocking it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Advanced hunting in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Defender portal
At security.microsoft.com, one place to work with Defender XDR, Microsoft Sentinel, Defender for Cloud Apps and further Microsoft security products.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- XDR
Extended detection and response: pulling together and linking threat signals from several areas, such as email, devices, identities and apps, instead of examining each in isolation. Microsoft offers this as Microsoft Defender XDR.
Related terms
- AADSignInEventsBeta
An advanced hunting table holding both interactive and non-interactive Microsoft Entra sign-ins, available with Entra ID P2. From 19 October 2026 EntraIdSignInEvents takes over from it, and existing queries move across automatically.
- AlertEvidence
Joined to AlertInfo through AlertId, this advanced hunting table lists the entities linked with each alert, for example files, IP addresses, URLs, users and devices.
- ARG
Azure Resource Graph lets you run KQL over deployed resources in many subscriptions at once. Log Analytics and advanced hunting can call it with arg(), while analytics rules and lake queries cannot.
- CloudAppEvents
Holds enriched activity from Office 365 and connected SaaS apps for advanced hunting. Data arrives only through Defender for Cloud Apps and its Microsoft 365 connector; Purview Audit by itself doesn't fill it.
- CloudAuditEvents
Fed by Microsoft Defender for Cloud, this advanced hunting table captures control-plane activity in the cloud, for example Azure Resource Manager operations or Kubernetes audit records.
- CloudProcessEvents
An advanced hunting table, fed by Microsoft Defender for Cloud, that records process activity across multicloud Kubernetes environments including AKS, EKS and GKE.
- Custom detection
Microsoft now suggests these Defender XDR rules when creating new detections for Sentinel or Defender XDR. Each is built on an advanced hunting query, runs periodically or in near real time (NRT), raises alerts and may take response actions.
- DataSecurityBehaviors
Daily summaries of possibly suspicious behaviour detected by Insider Risk Management, exposed for advanced hunting in preview. Data appears only once insider risk data is shared with Defender.