Microsoft Sentinel
Hunting and detection

Create custom hunting queries in Microsoft Sentinel

In brief

The article now describes writing, cloning, and editing KQL-based hunting queries, clarifies the navigation sequence, and specifies that queries from content hub solutions or repositories must be edited in their original source.

What Defender admins need to know

Administrators have clearer guidance for creating and maintaining custom hunting queries; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Create custom hunting queries in Microsoft Sentinel titleSuffix: Microsoft Sentinel description: Create custom hunting queries in Microsoft Sentinel to proactively investigate suspicious activity across your data sources. Learn how to create a custom query to huntwrite, clone, and edit KQL-based hunting queries for threats.threat investigation. ms.author: monaberdugo author: mberdugo ms.reviewer: efratka ms.topic: how-to ms.date: 06/15/07/01/2026 appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ms.collection: usx-security ai-usage: ai-assisted ms.custom: msecd-doc-authoring-10141016

#Customer intent: As a security analyst, I want to create and edit custom hunting queries so that I can proactively identify and mitigate security threats specific to my organization's environment.

Create a new query

In Microsoft Sentinel,To create a custom hunting query from thequery, first open Hunting >in Microsoft Sentinel, and then select the Queries tab.

  1. For Microsoft Sentinel in the Defender portal, select Microsoft Sentinel > Threat management > Hunting. For Microsoft Sentinel in the Azure portal, under Threat management select Hunting.

Edit an existing custom query

Only queries that come from a custom content source can be edited. Queries from other content sourcessources, such as content hub solutions or repositories, must be edited in their originalthe content source.source where the query was originally created.

  1. From the Hunting > Queries tab, select the hunting query you want to change.