Microsoft Sentinel
Cloud and workloads

Bookmarks

In brief

Updated metadata and wording clarify bookmark creation, Advanced hunting availability, MITRE ATT&CK mapping, the Bookmarks tab, incident viewing, and deletion behavior.

What Defender admins need to know

Administrators can use the clearer guidance when managing bookmarks; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

#Customer intent: As a security analyst, I want to create and manage hunting bookmarks so that I can preserve and collaborate on relevant threat investigation data.

This article explains how to create, view, and manage hunting bookmarks in Microsoft Sentinel and how to use them during investigations.

[!INCLUDE unified-soc-preview]

  1. On the right, in the Add bookmark pane, optionally, update the bookmark name, add tags, and notes to help you identify what was interesting about the item.

  2. BookmarksYou can be optionally mappedmap bookmarks to MITRE ATT&CK techniques or sub-techniques. MITRE ATT&CK mappings are inherited from mapped values in hunting queries, but you can also create them manually. Select the MITRE ATT&CK tactic associated with the desired technique from the drop-down menu in the Tactics & Techniques section of the Add bookmark pane. The menu expands to show all the MITRE ATT&CK techniques, and you can select multiple techniques and sub-techniques in this menu.

    :::image type="content" source="media/bookmarks/mitre-attack-mapping.png" alt-text="Screenshot of how to map Mitre Attack tactics and techniques to bookmarks.":::

View and update bookmarks

Find and update a bookmark from the bookmarkBookmarks tab.

  1. For Microsoft Sentinel in the Azure portal, under Threat management select Hunting.
    For Microsoft Sentinel in the Defender portal, select Microsoft Sentinel > Threat management > Hunting.

  2. Make your changes as needed. Your changes are automatically saved.

Exploring bookmarks in the investigation graph

- For a new incident: Optionally update the details for the incident, and then select **Create**.
- For adding a bookmark to an existing incident: Select one incident, and then select **Add**.
  1. To view the bookmark within the incident, incident:
    1. Go to Microsoft Sentinel > Threat management > Incidents.
    2. Select the incident with your bookmark and View full details.
    3. On the incident page, in the left pane, select the Bookmarks.

Delete a bookmark

Deleting the bookmark removes the bookmark from the list in the BookmarkBookmarks tab. The HuntingBookmark table for your Log Analytics workspace continues to contain previous bookmark entries, but the latest entry changes the SoftDelete value to true, which marks the bookmark as deleted so you can filter out old bookmarks. Deleting a bookmark doesn't remove any entities from the investigation experience that are associated with other bookmarks or alerts.

To delete a bookmark, complete the following steps.