Chapter 11: Threat Hunting in Microsoft Sentinel
Threat hunting is part science, part art, and part intuition. Usually, you are looking for something that may have happened in your environment. It may be that you think something has happened due to external events, such as something odd showing up in the workbooks, a notice from a threat intelligence feed, or even something you just read about on the internet, and you want to investigate. No matter what the reason is for performing your hunt, the tools in Microsoft Sentinel, including queries and the Jupyter Notebook, remain the same.
Threat hunting is a series of activities that you will perform during your investigation. While there is no set guidance on how to perform threat hunting, this chapter will introduce you to the tools that are available in Microsoft Sentinel to help you perform your investigations.
A brief introduction on how to perform threat hunting activities will also be discussed, which will include aspects...