Advanced hunting in the Defender portal lets you query up to 30 days of raw Defender XDR data with Kusto Query Language (KQL), and, when Sentinel is onboarded, Sentinel tables as well. A custom detection rule is a saved advanced hunting query that runs on a schedule and raises alerts, and optionally takes response actions, whenever it returns results. It is the Defender XDR counterpart of a Sentinel scheduled analytics rule, and its alerts join incidents in the same queue as built-in detections.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.