Microsoft Defender XDR
Hunting and detection

Advanced Hunting Security Copilot

In brief

The documentation now describes Rich insights and Query only modes, with Rich insights as the default. It updates mode-switching steps, notes that modes aren't available on non-primary workspaces, and explains that switching starts a new chat and clears the current conversation. It also documents support for queries spanning multiple tables.

What Defender admins need to know

Administrators should update guidance for users to reflect the new mode names, default behavior, workspace limitation, and conversation reset when switching modes.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • cx-ah ms.topic: how-to ms.update-cycle: 180-days ms.date: 06/16/07/02/2026 appliesto:
  • Microsoft Defender
  • Microsoft Defender XDR

[!INCLUDE Prerelease]

Microsoft Security Copilot in Microsoft Defender provides two powerful capabilitiesthe Threat Hunting Assistant in advanced hunting to enhance threat hunting and security analysis. The Threat Hunting Assistant runs in one of two modes, depending on how much help you want.

The following table describes these capabilities,each capability, where they're best used,to use it, and the expected output:

CapabilityMode Description Output Experience
Threat Hunting Agent (preview)Rich insights
Threat Hunting Assistant
AI-powered conversational threat hunting agentexperience that's best used for complete investigations, multistep hunting, exploratory analysis, and getting direct answers Conversational answers, Kusto query language (KQL) queries, results, insights, and recommendations Investigation-focused
Query only
Query assistant
Natural language to KQL query generation that's best used for generating queries KQL query with explanation Query-focused

The Threat Hunting AgentAssistant and Query assistant empower you to hunt threats faster, more accurately, and with greater confidence without needing to write KQL queries.

Get access to Security Copilot in advanced hunting

Users with access to Security Copilot can use these capabilities in advanced hunting.

You can only use one capabilitymode at a time. By default, the Threat Hunting AgentRich insights is the default mode. The active mode. mode appears as a badge next to Threat hunting assistant at the top of the Security Copilot side pane.

To switch to Query assistant mode,change modes, select the three-dot menu (More actions) in the Security Copilot side pane, select the three-dot menu, then toggle thepoint to Threat Huntinghunting assistant mode, then select Rich insights or Query only.

Screenshot of the Threat hunting assistant mode submenu in the Security Copilot side pane, showing Rich insights selected and Query only available.

To use the Security Analyst Agent instead, select Switch to Security Analyst Agent switch off.

Screenshot of Security Copilot in advanced hunting showing the Threat Hunting Agent mode is active.from the same menu.

To switch to Query assistant mode, in the Security Copilot side pane, select the three-dot menu, then toggle the Threat Hunting Agent switch off.

Screenshot of Security Copilot in advanced hunting showing the Threat Hunting Agent mode is active.

Scope of Security Copilot in advanced hunting

Use case support

The Threat Hunting Assistant handles questions ranging from simple filters and aggregations to queries that span several tables. When a question needs data from more than one table, the assistant selects the relevant tables and joins them.

As with any AI-generated content, review the generated query and its results before you act on them. Help us improve by providing feedback on Security Copilot in Microsoft Defender with incorrect queries or response examples.

Best practices

Use the following best practices when prompting the Threat Hunting AgentAssistant or Query assistant:

  • Be unambiguous. Ask questions with a clear subject. For example, "logins" could mean device logins or cloud logins.
  • Ask one question at a time. Ask for a single task or type of information at a time. Don't expect the AI model to perform several unrelated tasks at once. You can always ask follow-up questions instead of combining unrelated asks into a single prompt.
  • Be specific. If you know anything about the data you're looking for, provide that information in your question.

Supported tablesHow the assistant finds your data

The Threat Hunting AgentAssistant discovers the data available in your environment as it works, instead of using a fixed list of tables. For each question, it:

  1. Lists the tables you have access to.
  2. Inspects the schema of the tables that look relevant.
  3. Selects the tables needed to answer the question, and Query assistant support the followingjoins them when more than one is required.

This includes custom tables in advanced hunting:

Microsoft Defender tablesyour Microsoft Sentinel tables
  • AADSignInEventsBeta
  • AADSpnSignInEventsBeta
  • AlertEvidence
  • AlertInfo
  • BehaviorEntities
  • BehaviorInfo
  • CloudAppEvents
  • CloudAuditEvents
  • CloudDnsEvents
  • CloudProcessEvents
  • DeviceAlertEvents
  • DeviceBaselineComplianceAssessment
  • DeviceBaselineComplianceAssessmentKB
  • DeviceBaselineComplianceProfiles
  • DeviceEvents
  • DeviceFileCertificateInfo
  • DeviceFileEvents
  • DeviceImageLoadEvents
  • DeviceInfo
  • DeviceInternetFacing
  • DeviceLogonEvents
  • DeviceNetworkEvents
  • DeviceNetworkInfo
  • DeviceProcessEvents
  • DeviceRegistryEvents
  • DeviceScriptEvents
  • DeviceTvmInfoGathering
  • DeviceTvmInfoGatheringKB
  • DeviceTvmSecureConfigurationAssessment
  • DeviceTvmSecureConfigurationAssessmentKB
  • DeviceTvmSoftwareEvidenceBeta
  • DeviceTvmSoftwareInventory
  • DeviceTvmSoftwareVulnerabilities
  • DeviceTvmSoftwareVulnerabilitiesKB
  • DynamicEventCollection
  • EmailAttachmentInfo
  • EmailEvents
  • EmailPostDeliveryEvents
  • EmailUrlInfo
  • IdentityDirectoryEvents
  • IdentityInfo
  • IdentityLogonEvents
  • IdentityQueryEvents
  • UrlClickEvents
  • AADManagedIdentitySignInLogs
  • AADNonInteractiveUserSignInLogs
  • AADProvisioningLogs
  • AADRiskyUsers
  • AADServicePrincipalSignInLogs
  • AADUserRiskEvents
  • ABAPAuditLog_CL
  • AlertEvidence
  • AlertInfo
  • Anomalies
  • AppDependencies
  • AppTraces
  • AuditLogs
  • AWSCloudTrail
  • AWSGuardDuty
  • AzureActivity
  • AzureDevOpsAuditing
  • AzureDiagnostics
  • AzureMetrics
  • BehaviorAnalytics
  • CloudAppEvents
  • CloudAuditEvents
  • CloudDnsEvents
  • CloudProcessEvents
  • CommonSecurityLog
  • ContainerInventory
  • ContainerLog
  • DeviceEvents
  • DeviceFileCertificateInfo
  • DeviceFileEvents
  • DeviceImageLoadEvents
  • DeviceInfo
  • DeviceLogonEvents
  • DeviceNetworkEvents
  • DeviceNetworkInfo
  • DeviceProcessEvents
  • DeviceRegistryEvents
  • DnsEvents
  • Dynamics365Activity
  • EmailPostDeliveryEvents
  • Event
  • Heartbeat
  • IdentityInfo
  • InsightsMetrics
  • IntuneAuditLogs
  • IntuneDevices
  • LAQueryLogs
  • MicrosoftAzureBastionAuditLogs
  • MicrosoftPurviewInformationProtection
  • OfficeActivity
  • Perf
  • PowerBIActivity
  • ProtectionStatus
  • SecurityAlert
  • SecurityEvent
  • SecurityIncident
  • SecurityRecommendation
  • SigninLogs
  • SqlAtpStatus
  • StorageBlobLogs
  • StorageFileLogs
  • Syslog
  • ThreatIntelligenceIndicator
  • Update
  • UrlClickEvents
  • Usage
  • UserAccessAnalytics
  • UserPeerAnalytics
  • VMBoundPort
  • VMComputer
  • VMConnection
  • VMProcess
  • WindowsEvent
  • W3CIISLog
  • WindowsFirewall
workspace.

Discovery follows your own permissions, so the assistant only reaches data that you can already query in advanced hunting. It runs read-only queries and can't run commands that change data or configuration.