Instiq
Chapter 5 · Performing threat hunting·v1.0.0·Updated 6/28/2026·~12 min

What's changed: Created SC-200 Chapter 5 (Domain 3: hunting in Defender XDR (KQL table selection like DeviceProcessEvents/identify threats with KQL/create Advanced Hunting queries/interpret threat analytics); hunting graphs (blast radius)/entity-relationship analysis with Sentinel Graph; Sentinel platform (hunting queries/bookmarks/KQL jobs in Data lake/Summary rule tables/Notebooks and Sentinel MCP Server connection)).

5.2Hunting graphs and Sentinel Graph

Key points

Understand creating hunting graphs (including blast radius) and analyzing relationships between entities with Sentinel Graph.

Threats spread through "connections," not isolated "points." Viewing as a graph how far an entity’s (e.g., a compromised account’s) impact reaches and what it relates to lets you quickly grasp lateral movement and scope.

5.2.1Hunting graphs and blast radius

Hunting graphs visualize entities (devices, users, files, IPs) and their relationships, helping you follow the chain during a hunt—"which devices did this account touch? where next?" Blast radius shows "how far damage could reach" from a compromised entity, used to prioritize containment. Lateral-movement paths invisible in a list of points are obvious in a graph.

5.2.2Sentinel Graph

Sentinel Graph analyzes relationships between entities across the org-wide data aggregated in Sentinel. You explore relationships spanning multiple sources (identity, endpoint, cloud, network) as a graph, revealing cross-cutting connections hard to see in single-table KQL. Analysts use it to follow the full picture of multi-domain complex attacks, entity-first.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.