Microsoft Defender XDR
Hunting and detection

Advanced Hunting Go Hunt

In brief

The documentation date changed to July 2, 2026, and the wording now specifies that the associated incident includes the entity.

What Defender admins need to know

No administrator action is indicated; administrators have clearer guidance when reviewing the entity’s associated incident.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

You can use go hunt to query for information about a user, device, or any other type of entity; the query checks all relevant schema tables for any events involving that entity to return information. To keep the results manageable, the query is:

  • scoped to around the same time period as the earliest activity in the past 30 days that involves the entity
  • associated with the incident.incident that includes the entity.

Here is an example of the go hunt query for a device: