Microsoft Defender XDR
Hunting and detection

Advanced Hunting Link To Incident

In brief

The article date and wording were updated, with shorter instructions for running queries, confirming prerequisites, troubleshooting, creating alerts, viewing linked incidents, and filtering manually detected alerts.

What Defender admins need to know

Administrators can use the revised steps when following this workflow; no action is stated as required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

[!INCLUDE Microsoft Defender XDR rebranding]

Use the link to incident feature to add advanced hunting query results to a new or existing incident under investigation.incident. This feature helps you capture records from advanced hunting activities, including behavior-based results, so you canto create richer incident context.

Use the link to incidentYou can also use this feature to add advanced hunting query results to a new or existing incident under investigation. The link to incident feature helps you easily capture records from advanced hunting activities, which enablesactivities. These records help you to createbuild a richer timeline or context of events regardingfor an incident.

Required permissions for linking incidents

Use the following steps to link advanced hunting results to a new or existing incident.

  1. InOn the advanced hunting query page, first enter your query in the query field providedand then select Run query to get your results..

    :::image type="content" source="media/advanced-hunting-link-to-incident/link-to-incident-1.png" alt-text="Screenshot of the advanced hunting page in the Microsoft Defender portal." lightbox="media/advanced-hunting-link-to-incident/link-to-incident-1.png":::

When you query the BehaviorInfo table, you can link a single behavior record to a new or existing incident.

Before you start, make sureconfirm that behavior-based data sources are onboardedset up and that you havecan access to the BehaviorInfo and BehaviorEntities tables. You also need the permissions required to manage custom detections. For more information, see Required permissions for linking incidents.

This preview follows existing RBAC and incident scoping policies. If Link to incident isn't available,available or if the wizard doesn't populate entities as expected, verifyshow entities, check your table access, data source onboarding,setup, and incident scope.

In this workflow, you select one BehaviorId at a time. The wizard creates one alert per selected behavior,behavior. It fills in alert details and alert metadata and entities are automatically enriched from the selected behavior record. You can review and edit the auto-populated fields, and severitythese fields. Severity and recommended actions remainstay under your control.

  1. In the advanced hunting query page, run a query on the BehaviorInfo table to retrieve behavior records.

View linked records in the incident

To view the incident the events are linked to,incident, select the generated link fromshown in the summary step of the wizard, orstep. You can also select the incident name from the incident queue.

:::image type="content" source="media/advanced-hunting-results-link7.png" alt-text="Screenshot of the summary step in the link to incident wizard in the Microsoft Defender portal." lightbox="media/advanced-hunting-results-link7.png":::

In ourthis example, the alert created from the selected event was linked successfully to a new incident. InOn the alert page, you can findview full event details in the complete information on the event in timeline view (if available) and the query results view.

You can also select the event from the timeline view or from the query results view to open the Inspect record pane.

Filter for events added using advanced hunting

You can view whichTo find alerts were generatedcreated from advanced hunting by filteringhunting, filter incidents and alerts by the Manual detection source.

:::image type="content" source="media/advanced-hunting-results-link9.png" alt-text="Screenshot of the filter dropdown in advanced hunting in the Microsoft Defender portal." lightbox="media/advanced-hunting-results-link9.png":::