Microsoft Defender XDR
Hunting and detection

Advanced Hunting Shared Queries

In brief

The page date moved to July 2, 2026. Wording now describes query sections as lists or groups, simplifies rename and delete instructions, updates the GitHub contribution link, and directs readers to threat analytics reports in the Defender portal.

What Defender admins need to know

Administrators have clearer guidance for locating and managing shared, personal, and community queries.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • cx-ti
  • cx-ah ms.topic: how-to ms.date: 06/16/07/02/2026 appliesto:
  • Microsoft Defender XDR
  • Microsoft Sentinel in the Microsoft Defender portal

[!INCLUDE Microsoft Defender XDR rebranding]

Advanced hunting queries can be shared with users in your organization. You can also save queries that only you can access. Community queries shared on GitHub are available too. TheseWith saved queries helpqueries, you can quickly start hunting for threats without writingthreats. You don't need to write queries from scratch.

The Queries tab in advanced hunting has drop-down menus forlists Shared queries, My queries, and Community queries. Select an arrow to expand a menu.group.

:::image type="content" source="media/advanced-hunting-shared-queries/advanced-hunting-shared-queries-1.png" alt-text="Shared queries, My queries, and Community queries in the Microsoft Defender portal" lightbox="media/advanced-hunting-shared-queries/advanced-hunting-shared-queries-1.png":::

Delete or rename a query

ToYou can rename or delete a saved query or delete one you no longer need, follow these steps:at any time.

  1. Find the query you want to change.query. Select the three dots next to its right.it.

    :::image type="content" source="media/advanced-hunting-shared-queries/advanced-hunting-del-save-query.png" alt-text="Rename or delete a query in the Advanced Hunting page in the Microsoft Defender portal" lightbox="media/advanced-hunting-shared-queries/advanced-hunting-del-save-query.png":::

Access community queries in the GitHub repo

Microsoft security researchers share advanced hunting queries in a public GitHub repository. All contributionsqueries are reviewed before they're published. To contribute, join GitHub for free.

You can easilyalso find these queries in the Community queries drop-down menu as well.list.

:::image type="content" source="media/advanced-hunting-shared-queries/advanced-hunting-shared-queries-2.png" alt-text="Community queries organized by folder in the Microsoft Defender portal" lightbox="media/advanced-hunting-shared-queries/advanced-hunting-shared-queries-2.png":::

Community queries are grouped into folders such as Campaigns, Collection, and Defense evasion. Each query includes in-line comments with more details.

Related content