Chapter 11: Threat Hunting in Microsoft Sentinel

Threat hunting is part science, part art, and part intuition. Usually, you are looking for something that may have happened in your environment. It may be that you think something has happened due to external events, such as something odd showing up in the workbooks, a notice from a threat intelligence feed, or even something you just read about on the internet, and you want to investigate. No matter what the reason is for performing your hunt, the tools in Microsoft Sentinel, including queries and the Jupyter Notebook, remain the same.

Threat hunting is a series of activities that you will perform during your investigation. While there is no set guidance on how to perform threat hunting, this ...

Get Microsoft Sentinel in Action - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.