Instiq

5Performing threat hunting

Practice questions →Glossary →
  • 5.1Hunting and KQL in Defender XDR

    Understand selecting the appropriate table for a KQL query, identifying threats with Kusto Query Language (KQL), creating Advanced Hunting queries, and interpreting threat analytics in Microsoft Defender XDR.

  • 5.2Hunting graphs and Sentinel Graph

    Understand creating hunting graphs (including blast radius) and analyzing relationships between entities with Sentinel Graph.

  • 5.3Hunting on the Sentinel platform

    Understand creating/monitoring Microsoft Sentinel hunting queries, creating/managing KQL jobs in Data lake, creating/managing Summary rule tables, and hunting with Notebooks (including connecting to the Sentinel MCP Server).