Proactive threat searches written in KQL and saved in Microsoft Sentinel's Hunting area, run against the workspace.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Hunting queries in context, with comparison tables and the common traps.
Terms in this definition
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
Related terms
- Content hub
Lets you browse and install Microsoft Sentinel solutions, or standalone items such as playbooks, workbooks, hunting queries, analytics rules and data connectors, all supplied out of the box.
- Threat hunting
Actively looking through security data for signs of attack without waiting to be alerted. In Microsoft Sentinel, analysts run hunting queries linked to MITRE ATT&CK; Defender XDR adds advanced hunting written in KQL, plus custom detection rules.