Hunting Overview
In brief
The overview replaces the Infrastructure chaining entry with a Threat analytics link for tracking emerging threats and reviewing Microsoft threat research and insights. The reactive hunting table formatting was also adjusted.
What Defender admins need to know
Administrators looking for threat research from the hunting overview should use the new Threat analytics link; no configuration changes are required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
|MITRE ATT&CK map | When creating a new hunting query, select specific tactics and techniques to apply.|
|Restore historical data | Restore data from archived logs to use in high performing queries. |
|Search large data sets | Search for specific events in logs up to seven years ago using KQL. |
|Infrastructure chaining Threat analytics | Hunt for new connections betweenTrack emerging threats and review Microsoft threat actors, group similar attack activityresearch and substantiate assumptions.insights. |
|Threat explorer | Hunt for specialized threats related to email. |
Hunting stages
| Hunting stage | Hunting tools |
|---|---|
| Proactive - Find the weak areas in your environment before threat actors do. Detect suspicious activity extra early. | - Regularly conduct end-to-end hunts to proactively seek out undetected threats and malicious behaviors, validate hypotheses, and act on findings by creating new detections, incidents, or threat intelligence. - Use the MITRE ATT&CK map to identify detection gaps, and then run predefined hunting queries for highlighted techniques. - Insert new threat intelligence into proven queries to tune detections and confirm if a compromise is in process. - Take proactive steps to build and test queries against data from new or updated sources. - Use advanced hunting to find early-stage attacks or threats that don't have alerts. |
| Reactive - Use hunting tools during an active investigation. | - Use livestream to run specific queries at consistent intervals to actively monitor events. - Quickly pivot on incidents with the Go hunt button to search broadly for suspicious entities found during an investigation. - - Use Security Copilot in advanced hunting to generate queries at machine speed and scale. |
| Post incident - Improve coverage and insights to prevent similar incidents from recurring. | - Turn successful hunting queries into new analytics and detection rules, or refine existing ones. - Restore historical data and search large datasets for specialized hunting as part of full incident investigations. |
@@ -41,7 +41,7 @@ Maximize the full extent of your team's hunting prowess with the following hunti |[**MITRE ATT&CK map**](/azure/sentinel/mitre-coverage#use-the-mitre-attck-framework-in-analytics-rules-and-incidents) | When creating a new hunting query, select specific tactics and techniques to apply.| |[**Restore historical data**](/azure/sentinel/restore) | Restore data from archived logs to use in high performing queries. | |[**Search large data sets**](/azure/sentinel/search-jobs?tabs=defender-portal) | Search for specific events in logs up to seven years ago using KQL. |-|[**Infrastructure chaining**](/defender/threat-intelligence/infrastructure-chaining) | Hunt for new connections between threat actors, group similar attack activity and substantiate assumptions.|+| [**Threat analytics**](/defender-xdr/threat-analytics) | Track emerging threats and review Microsoft threat research and insights. | |[**Threat explorer**](/defender-office-365/threat-explorer-threat-hunting) | Hunt for specialized threats related to email. | ## Hunting stages@@ -51,7 +51,7 @@ The following table describes how you can make the most of the Defender portal's | Hunting stage | Hunting tools | | --- | --- | | **Proactive** - Find the weak areas in your environment before threat actors do. Detect suspicious activity extra early. | - Regularly conduct end-to-end [hunts](/azure/sentinel/hunts) to proactively seek out undetected threats and malicious behaviors, validate hypotheses, and act on findings by creating new detections, incidents, or threat intelligence.<br><br> - Use the [MITRE ATT&CK map](/azure/sentinel/mitre-coverage#use-the-mitre-attck-framework-in-analytics-rules-and-incidents) to identify detection gaps, and then run predefined hunting queries for highlighted techniques.<br><br> - Insert new threat intelligence into proven queries to tune detections and confirm if a compromise is in process.<br><br> - Take proactive steps to build and test queries against data from new or updated sources.<br><br> - Use [advanced hunting](/defender-xdr/advanced-hunting-microsoft-defender) to find early-stage attacks or threats that don't have alerts. |-| **Reactive** - Use hunting tools during an active investigation. | - Use [livestream](/azure/sentinel/livestream) to run specific queries at consistent intervals to actively monitor events.<br><br> - Quickly pivot on incidents with the [**Go hunt**](/defender-xdr/advanced-hunting-go-hunt) button to search broadly for suspicious entities found during an investigation.<br><br> - Hunt through threat intelligence to perform [infrastructure chaining](/defender/threat-intelligence/infrastructure-chaining).<br><br> - Use [Security Copilot in advanced hunting](/defender-xdr/advanced-hunting-security-copilot) to generate queries at machine speed and scale. |+| **Reactive** - Use hunting tools during an active investigation. | - Use [livestream](/azure/sentinel/livestream) to run specific queries at consistent intervals to actively monitor events.<br><br> - Quickly pivot on incidents with the [**Go hunt**](/defender-xdr/advanced-hunting-go-hunt) button to search broadly for suspicious entities found during an investigation.<br><br> - Use [threat analytics](/defender-xdr/threat-analytics) to investigate emerging threats and assess their potential impact.<br><br> - Use [Security Copilot in advanced hunting](/defender-xdr/advanced-hunting-security-copilot) to generate queries at machine speed and scale. | | **Post incident** - Improve coverage and insights to prevent similar incidents from recurring. | - Turn successful hunting queries into new [analytics and detection rules](/azure/sentinel/threat-detection), or refine existing ones.<br><br> - [Restore historical data](/azure/sentinel/restore) and [search large datasets](/azure/sentinel/search-jobs?tabs=defender-portal) for specialized hunting as part of full incident investigations. | 