StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 3: Perform threat hunting

Graph-based hunting: Sentinel graph and hunting graphs with blast radius

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Tables and Kusto Query Language (KQL) are great for asking which events match a condition, but many security questions are about relationships: which users can reach this storage account, how could a compromised laptop lead to a domain admin, or what would an attacker holding this identity be able to touch. Graphs model data as nodes (users, devices, groups, cloud resources, applications) and edges (relationships such as member of, has permission to, logged on to or can authenticate as). Attackers think in graphs, moving from one foothold to the next, so defenders benefit from doing the same.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan