5Performing threat hunting
- 5.1Hunting and KQL in Defender XDR
Understand selecting the appropriate table for a KQL query, identifying threats with Kusto Query Language (KQL), creating Advanced Hunting queries, and interpreting threat analytics in Microsoft Defender XDR.
- 5.2Hunting graphs and Sentinel Graph
Understand creating hunting graphs (including blast radius) and analyzing relationships between entities with Sentinel Graph.
- 5.3Hunting on the Sentinel platform
Understand creating/monitoring Microsoft Sentinel hunting queries, creating/managing KQL jobs in Data lake, creating/managing Summary rule tables, and hunting with Notebooks (including connecting to the Sentinel MCP Server).

