StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 1: Manage a security operations environment

Custom detection rules in Defender XDR advanced hunting; MITRE ATT&CK coverage of your rules

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Advanced hunting in the Defender portal lets you query up to 30 days of raw Defender XDR data with Kusto Query Language (KQL), and, when Sentinel is onboarded, Sentinel tables as well. A custom detection rule is a saved advanced hunting query that runs on a schedule and raises alerts, and optionally takes response actions, whenever it returns results. It is the Defender XDR counterpart of a Sentinel scheduled analytics rule, and its alerts join incidents in the same queue as built-in detections.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan