Microsoft Defender XDR
Hunting and detection

Manage custom detection rules in Microsoft Defender XDR

In brief

The article now explicitly covers viewing, editing, running, enabling, disabling, and deleting custom detection rules, along with reviewing triggered alerts and response actions. Headings, an anchor, and the publication date were also updated.

What Defender admins need to know

Administrators have clearer documentation for managing custom detection rules in Microsoft Defender XDR; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

[!INCLUDE Microsoft Defender XDR rebranding]

This article explains how to view, edit, run, enable, disable, and delete custom detection rules built from advanced hunting queries in Microsoft Defender XDR. You can also review triggered alerts and response actions for each rule.

ManageAvailable management actions for custom detection rules

You can view the list of existing custom detection rules, check their previous runs, and review the alerts that were triggered. You can also run a rule on demand, modify it, or create a new custom detection rule directly from the list.

View and manage triggered alerts

In the rule details screen (Hunting > Custom detections > [Rule name]), go to Triggered alerts, which lists the alerts generated by matches to the rule. Select an alert to view detailed information about it and take the following actions:

  • Link the alert to an incident
  • Run the query that triggered the alert on advanced hunting

Review actions

In the rule details screen (Hunting > Custom detections > [Rule name]), go to Triggered actions, which lists the actions taken based on matches to the rule.