Understanding advanced hunting
Advanced hunting is a powerful tool for proactively hunting threats by querying up to 30 days of raw data. It allows for a comprehensive examination of events in your Microsoft 365 Defender (M365D) environment to identify potential threats and entities. With flexible access to data, you can search for both known and unknown threats.
There are two modes of advanced hunting: guided and advanced. The guided mode is suitable for those who are not familiar with KQL or prefer the ease of using a query builder. On the other hand, the advanced mode is recommended for users comfortable with creating KQL queries from scratch.
Advanced hunting enables the creation of custom detection rules by supporting queries that cover a wider range of datasets from different Microsoft Defender products, such as Microsoft Defender for Endpoint (MDE), Microsoft Defender for Office 365 (MDO), Microsoft Defender for Cloud Apps (MDA), and Microsoft Defender for Identity (MDI...