Microsoft Defender XDR
Hunting and detection

GetFirstSeenBehaviors() function in advanced hunting for Microsoft Defender XDR

In brief

The new reference explains how to invoke GetFirstSeenBehaviors() to return rows containing a FirstSeen insight, with an example using recent Microsoft Sentinel BehaviorInfo data.

What Defender admins need to know

Administrators can use the function to identify behaviors observed for the first time. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

new file mode 100644

title: GetFirstSeenBehaviors() function in advanced hunting for Microsoft Defender XDR description: Learn how to use the GetFirstSeenBehaviors() function to find UEBA behaviors that contain FirstSeen insights. ms.service: defender-xdr ms.subservice: adv-hunting ms.author: pauloliveria author: poliveria ms.localizationpriority: medium ms.collection:

  • m365-security
  • tier3 ms.custom:
  • cx-ti
  • cx-ah appliesto:
    • Microsoft Defender XDR
    • Microsoft Sentinel in the Microsoft Defender portal ms.topic: reference ms.date: 07/15/2026

GetFirstSeenBehaviors()

Use the GetFirstSeenBehaviors() function in advanced hunting to return behaviors that contain at least one FirstSeen insight in the Insights column.

A FirstSeen insight indicates that a behavior, entity, value, or combination of values was observed for the first time.

Syntax

invoke GetFirstSeenBehaviors()

Parameters

This function has no explicit parameters. Invoke it as part of a query on a tabular input that contains an Insights column of type string.

Return value

Returns the rows from the input table that contain at least one FirstSeen insight. All columns from the input table are preserved.

Example

Find recent Microsoft Sentinel behaviors with FirstSeen insights

BehaviorInfo
| where ServiceSource == "Microsoft Sentinel"
| where TimeGenerated > ago(1d)
| invoke GetFirstSeenBehaviors()
| project TimeGenerated, BehaviorId, Title, Insights

Related content