Working with Azure Sentinel Hunting queries
While there are a lot of pre-existing queries, with more being added all the time, there may be times when you need to add your own or modify an existing query to better suit your needs.
Adding a new query
To add a new query, click on the New Query button at the top of the Hunting page. This will open the Create custom query page, as shown in the following screenshot. This is very similar to creating a new scheduled query, as discussed in Chapter 7, Creating Analytic Rules, so you can read the Creating a new rule using the wizard section as a refresher:
Fill in the Name, Description, and Custom query fields. If your query has any entities, use the Entity mapping section to add the entity mapping to the query. Remember to add them one at a time. Finally, select one or more tactics (not shown in the screenshot) that this query is using.
Once all the information has been...