Microsoft now suggests these Defender XDR rules when creating new detections for Sentinel or Defender XDR. Each is built on an advanced hunting query, runs periodically or in near real time (NRT), raises alerts and may take response actions.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Custom detection in context, with comparison tables and the common traps.
Terms in this definition
- XDR
Extended detection and response: pulling together and linking threat signals from several areas, such as email, devices, identities and apps, instead of examining each in isolation. Microsoft offers this as Microsoft Defender XDR.
- Advanced hunting
Threat-hunting feature of the Microsoft Defender portal that runs KQL over 30 days of raw Defender XDR data, plus onboarded Sentinel data, and supports custom detections. It finds activity after it happens rather than blocking it.
- Agents (classic) API
First-generation Foundry Agent Service API, based on threads, messages and runs. It is deprecated, replaced by conversations and responses, and retires on 31 March 2027.
Related terms
- STDOUT
The normal output of a script. For a custom detection script on an Intune Win32 app, the app only counts as installed if the script writes something there and exits with code 0.
- Threat hunting
Actively looking through security data for signs of attack without waiting to be alerted. In Microsoft Sentinel, analysts run hunting queries linked to MITRE ATT&CK; Defender XDR adds advanced hunting written in KQL, plus custom detection rules.