3Configuring detections
- 3.1Custom detection rules in Defender XDR
Understand creating and managing custom detection rules using Advanced Hunting in Microsoft Defender XDR.
- 3.2Sentinel analytics rules and anomalies
Understand configuring/managing Microsoft Sentinel analytics rules (scheduled, near-real-time NRT, threat intelligence, machine learning) and Sentinel anomalies.
- 3.3Analyzing coverage with MITRE ATT&CK
Understand using the MITRE ATT&CK matrix to analyze attack-vector coverage from analytics rules and hunting queries, visualizing detection gaps.

