Microsoft Defender XDR
Hunting and detection

Microsoft Security Copilot advanced hunting query assistant

In brief

The page now refers to Security Copilot’s Threat Hunting Assistant and explains how to run a generated query, add it to the editor for review, and view its logic. Screenshots, image descriptions, feedback wording, and the page date were also updated.

What Defender admins need to know

Administrators get refreshed instructions for reviewing and running generated queries. No administrator action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Microsoft Security Copilot advanced hunting query assistant description: Learn how Microsoft Security Copilot threat hunting agentThreat Hunting Assistant can help you generate a KQL query. ms.service: defender-xdr ms.subservice: adv-hunting ms.author: pauloliveria

  • cx-ti
  • cx-ah ms.topic: how-to ms.date: 06/16/07/02/2026 appliesto:
  • Microsoft Defender
  • Microsoft Defender XDR
  1. Copilot generates a KQL query from your text instruction or question. While Copilot is generating, you can cancel the query generation by selecting Stop generating.

    Screenshot of Security Copilot in advanced hunting showing generated query results with Add and run and Add to editor options.

  2. Review the generated query. To check how Copilot came up with the query, you can select See the logic behind the query below the query text to expand the explanation behind the query. Select itSee the logic behind the query again to minimize.minimize the explanation.

    Screenshot of Security Copilot option to see the logic behind the query.

    You can then choose to run the query by selecting Run query.

    Screenshot of Security Copilot showing the Run query option.

    The generated query appears as the last query in the query editor and runs automatically.

    The generated query appears in the query editor as the last query, where you can edit it before running using the regular Run query above the query editor.

  3. You can provide feedback about the generated response by selecting the feedback icon Screenshot of Security Copilot feedback option in advanced hunting. and choosing Looks right, Needs improvement, or Inappropriate.

Run or add the generated query

When the Threat Hunting Assistant generates a KQL query, select Run query to run it in advanced hunting.

To review or edit the query before running it, select the arrow next to Run query, then select Add to editor. The query is added to the query editor without running.

Screenshot of the Run query split button in the Security Copilot side pane, showing the Add to editor option.

To see how the query was constructed, select See the logic behind the query.