Microsoft Defender XDR
General

Work with results containing Microsoft Sentinel data

In brief

The article now explains how to explore and act on query results containing Microsoft Sentinel data, including linking results to incidents and taking response actions. It also adds inline inspection guidance and updates wording and formatting.

What Defender admins need to know

Administrators can more easily find guidance for reviewing results and adding records to incidents; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Explore advanced hunting results

Use the following options to inspect and work with advanced hunting results inline.

:::image type="content" source="media/advanced-hunting-defender-results/advanced-hunting-unified-results.png" alt-text="Screenshot of advanced hunting results with options to expand result rows in the Microsoft Defender portal" lightbox="/defender/media/advanced-hunting-unified-results.png":::

Link query results to an incident

You can use the link to incident feature to add advanced hunting query results to a new or existing incident under investigation. The linkLink to incident feature helps you easily capture records from advanced hunting activities, which allows you to create a richer timeline or context of events regarding an incident.

Link results to new or existing incidents

  1. After an entity type is selected, select an identifier type that exists in the selected records so that it can be used to identify this entity. Each entity type has a list of supported identifiers, as can be seen in the relevant drop down. Read the description displayed when hovering over each identifier to better understand the identifier.
  2. After selecting the identifier, select a column from the query results that contain the selected identifier. You can select Explore query and results to open the advanced hunting context panel. The advanced hunting context panel allows you to explore your query and results to make sure you chose the right column for the selected identifier.
    :::image type="content" source="media/advanced-hunting-defender-results-identifier.png" alt-text="Screenshot of the link to incident wizard entities branch in the Microsoft Defender portal" lightbox="media/advanced-hunting-defender-results-identifier.png":::