Advanced Hunting Go Hunt
In brief
The documentation date changed to July 2, 2026, and the wording now specifies that the associated incident includes the entity.
What Defender admins need to know
No administrator action is indicated; administrators have clearer guidance when reviewing the entity’s associated incident.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
You can use go hunt to query for information about a user, device, or any other type of entity; the query checks all relevant schema tables for any events involving that entity to return information. To keep the results manageable, the query is:
- scoped to around the same time period as the earliest activity in the past 30 days that involves the entity
- associated with the
incident.incident that includes the entity.
Here is an example of the go hunt query for a device:
@@ -17,7 +17,7 @@ appliesto: - Microsoft Defender XDR - Microsoft Sentinel in the Microsoft Defender portal ms.topic: how-to-ms.date: 06/16/2026+ms.date: 07/02/2026 ai-usage: ai-assisted --- @@ -50,7 +50,7 @@ Selecting **Go hunt** or **Hunt for related events** passes different queries, d You can use *go hunt* to query for information about a user, device, or any other type of entity; the query checks all relevant schema tables for any events involving that entity to return information. To keep the results manageable, the query is: - scoped to around the same time period as the earliest activity in the past 30 days that involves the entity-- associated with the incident.+- associated with the incident that includes the entity. Here is an example of the go hunt query for a device: 