Instiq
Chapter 5 · Performing threat hunting·v1.0.0·Updated 6/29/2026·~12 min

What's changed: Created SC-200 Chapter 5 (Domain 3: hunting in Defender XDR (KQL table selection like DeviceProcessEvents/identify threats with KQL/create Advanced Hunting queries/interpret threat analytics); hunting graphs (blast radius)/entity-relationship analysis with Sentinel Graph; Sentinel platform (hunting queries/bookmarks/KQL jobs in Data lake/Summary rule tables/Notebooks and Sentinel MCP Server connection)).

5.2Hunting graphs and Sentinel Graph

Key points

Understand creating hunting graphs (including blast radius) and analyzing relationships between entities with Sentinel Graph.

Threats spread through "connections," not isolated "points." Viewing as a graph how far an entity’s (e.g., a compromised account’s) impact reaches and what it relates to lets you quickly grasp lateral movement and scope.

5.2.1Hunting graphs and blast radius

Hunting graphs visualize entities (devices, users, files, IPs) and their relationships, helping you follow the chain during a hunt—"which devices did this account touch? where next?" Blast radius shows "how far damage could reach" from a compromised entity, used to prioritize containment. Lateral-movement paths invisible in a list of points are obvious in a graph.

5.2.2Sentinel Graph

Sentinel Graph analyzes relationships between entities across the org-wide data aggregated in Sentinel. You explore relationships spanning multiple sources (identity, endpoint, cloud, network) as a graph, revealing cross-cutting connections hard to see in single-table KQL. Analysts use it to follow the full picture of multi-domain complex attacks, entity-first.

Exam point

Cues: "follow the entity chain and visualize scope" = hunting graph. "how far damage reaches from a compromise origin" = blast radius. "analyze entity relationships across org-wide data" = Sentinel Graph. Grasp lateral movement in a graph that a list of points (KQL table) hides.

Warning

Watch the mix-ups: (1) Hunting graphs (visualizing entity chains during a hunt) and Sentinel Graph (cross-org relationship analysis) are close but different contexts. (2) Blast radius is "scope estimation"—not a containment action itself. (3) Graphs complement the tabular KQL view as a different lens.

Diagram of hunting graphs (visualize entity chains), blast radius (scope from a compromise origin to prioritize containment), and Sentinel Graph (cross-org entity-relationship analysis).
See by connections

5.2.3Section summary

  • Hunting graph = visualize entity chains; blast radius = scope from a compromise origin to prioritize containment
  • Sentinel Graph = analyze entity relationships across org-wide data (full picture of multi-domain attacks)
  • Graphs complement the tabular KQL view, showing lateral-movement paths at a glance

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. From a compromised account, you want to estimate "how far damage could reach" and prioritize containment. Which concept is best?

Q2. You want to analyze relationships between entities (users/devices/IPs) as a graph across org-wide data. Which is best?

Q3. During a hunt, you want to follow the chain "which devices did this account touch? where next?" Which is best?

Q4. How does a graph view excel over the tabular KQL view?

Q5. Which correctly characterizes blast radius?

Check your understandingPractice questions for Chapter 5: Performing threat hunting

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.