Chapter 10: Threat Hunting in Azure Sentinel
Threat hunting is part science, part art, and part intuition. Usually, you are looking for something that may have happened in your environment. It may be that you think something has happened due to external events, such as something odd showing up in the workbooks, a notice from a threat intelligence feed, or even something you just read about on the internet, and you want to investigate. No matter why you are performing your hunt, the tools in Azure Sentinel, including queries and Jupyter Notebooks, remain the same.
Threat hunting is a series of activities that you will perform during your investigation. While there is no set guidance on how to perform threat hunting, this chapter will introduce you to the tools that are available in Azure Sentinel to help you perform your investigations.
A brief introduction on how to perform threat-hunting activities will also be discussed, which will include aspects such as how to determine where...