Proactive threat hunting assumes attackers may already be inside and undetected, and searches for them rather than waiting for an alert. Microsoft Sentinel provides a set of tools that support each step: finding ideas, running queries, saving evidence, watching for new activity, and doing advanced analysis. The overall flow is to pick a hypothesis, run hunting queries or write new Kusto Query Language (KQL), bookmark evidence, use livestream to watch for more, go deeper in a notebook if needed, then turn findings into incidents and new detections. The Hunting page (Threat management, Hunting) lists hunting queries. Many come from Content hub solutions and are mapped to MITRE ATT&CK tactics and techniques; you can also write your own. Each query shows how many results it returns and whether that number changed recently. You can run all queries at once, sort by result count or change, and filter by tactic or data source. A query that suddenly returns results it did not before deserves a look. Hunting queries do not create alerts on their own; they run when you run them.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.