Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium

A security analyst is performing proactive threat hunting in Microsoft Sentinel. The analyst wants to search for unusual processes launched from temporary directories across all Windows endpoints. Which Sentinel feature is specifically designed for interactive, iterative query capabilities to discover new threats?

  1. AWatchlists
  2. BWorkbooks
  3. CAnalytics rules
  4. DHunting queries
Show answer & explanation

Correct answer: D. Hunting queries

Hunting queries in Microsoft Sentinel are specifically designed for proactive, interactive threat hunting. They allow security analysts to write and refine KQL queries to discover new threats or anomalies that built-in analytics rules might not detect.

Why the other options are wrong

  • A. Watchlists are used to enrich data with external threat intelligence or business-specific data, not for querying or threat hunting directly.
  • B. Workbooks are for data visualization and monitoring, not for interactive threat discovery.
  • C. Analytics rules are for automated detection and incident generation, not interactive exploration.

Microsoft Sentinel Hunting Queries

Kusto Query Language (KQL) queries used by security analysts to proactively search for threats, anomalies, or suspicious activities within their ingested data, often leading to new detection rules.

  • Designed for interactive and iterative exploration of data.
  • Helps discover 'unknown unknowns' that automated rules might miss.
  • Can be saved and shared as hunting queries or converted into analytics rules.

Memory trick: Think of it as a 'fishing expedition' – you're actively casting a net to see what you catch.

More Mitigate threats using Microsoft Sentinel questions