StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 3: Perform threat hunting

Turning a hunting query into a custom detection rule; Security Copilot help with writing KQL

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Hunting is exploratory: you form a hypothesis, query, and learn. When a hunt finds something worth watching for continuously, you promote it into a detection so the next occurrence raises an alert without a human remembering to look. In Defender XDR that means a custom detection rule; in Sentinel, a scheduled or near-real-time (NRT) analytics rule. The move from hunt to detection is how a security operations center (SOC) turns one analyst's insight into permanent coverage.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan