Loading...

Hunt in Microsoft 365 Defender without KQL!

Hunt in Microsoft 365 Defender without KQL!

Threat Hunting is critical to any effective Security Operations Center (SOC). Proactively hunting for threats strengthens the detection and protection coverage and can limit the impact an attack can have on any given environment. Actively detecting adversaries, mitigating the findings quickly, and implementing protection and prevention capabilities to prevent future instances all strengthen an organization’s defenses.

 

To reduce the learning curve for hunting and enable all analysts to hunt easily, we are excited to announce that a Guided hunting experience in Microsoft 365 Defender is now in public preview! This removes previous dependencies on KQL.

 

The guided experience in Microsoft 365 Defender is a new hunting mode that enables analysts with any level of experience to hunt without any knowledge of the Kusto Query Language (KQL) or the associated data schema. The new mode enables you to use the new query builder to construct your queries. You just need to know what you are looking for and you can easily hunt for it.

 

Microsoft 365 Defender hunting is the place to hunt for threats across workloads including devices, identities, emails, documents, and cloud apps. The data is equally available in both modes, the only difference is how you build the query. In the advanced mode, you craft a KQL query from scratch, and in the guided mode it is via a friendly query builder UI that wraps the KQL for you behind the scenes.

 

Guided mode provides an easy-to-use query builder with an interface that uses building blocks to construct queries through dropdown menus and provides filters to apply additional conditions:

 

Image 1: New guided hunting query builder interfaceImage 1: New guided hunting query builder interface

 

You can either start off with the basic filters set and load sample queries as shown above, or view and use more filters as seen below:

Image 2: Guided hunting query builder using advanced filteringImage 2: Guided hunting query builder using advanced filtering

 

For instance, you can use query builder to hunt for high confidence phish or spam email delivered to an inbox.

 

More information:

We encourage you to explore how guided mode can help you expand your incident investigations, perform analytics on threat data, or focus on specific threat areas. Read more about guided mode in our documentation:

This enhancement is available today in public preview. We would love to know what you think. Please share your feedback with us in the Microsoft 365 Defender portal or by emailing [email protected].

 

Published on:

Learn more
Microsoft 365 Defender Blog articles
Microsoft 365 Defender Blog articles

Microsoft 365 Defender Blog articles

Share post:

Related posts

Monthly news - November 2024

Microsoft Defender XDRMonthly newsNovember 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and v...

1 year ago

Monthly news - August 2024

Microsoft Defender XDRMonthly newsAugust 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and var...

1 year ago

Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

New Security Copilot skill: Identity Summary

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Demystify potential data leaks with Insider Risk Management insights in Defender XDR

In today's complex security landscape, understanding and mitigating data exfiltration risks is more critical than ever. Earlier this year, we ...

1 year ago

Monthly news - October 2024

Microsoft Defender XDRMonthly newsOctober 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and va...

1 year ago

AI-Driven Guided Response for SOCs with Microsoft Copilot for Security

In today's evolving cybersecurity landscape, security operation centers (SOCs) are constantly bombarded with incidents ranging from minor aler...

1 year ago

Identity Summary: New Security Copilot skill within Defender XDR

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Detecting browser anomalies to disrupt attacks early

Detecting browser anomalies is crucial for early identification and prevention of cyber threats, preventing data breaches and attacks by monit...

1 year ago

Microsoft Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.