Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A security operations team wants to proactively identify potential threats in their environment that are not yet detected by existing analytics rules. They suspect that a new type of malware might be present, exhibiting unusual process execution patterns and network connections that are not covered by current alerts. Which Microsoft Sentinel feature should the team primarily utilize for this purpose?
- AWorkbooks
- BPlaybooks
- CHunting Queries
- DAutomation Rules
Show answer & explanationAnswer & explanation
Correct answer: C. Hunting Queries
Hunting Queries are specifically designed for proactive threat hunting, allowing analysts to explore raw data for anomalies and indicators of compromise that current detection rules might miss.
Why the other options are wrong
- A. Workbooks are for data visualization and dashboards, not for active threat discovery.
- B. Playbooks (Logic Apps) are for automated response actions, typically triggered by incidents or alerts, not for proactive hunting.
- D. Automation Rules are for automating responses to *existing* incidents, not for proactive threat discovery.
Microsoft Sentinel Hunting Queries
Hunting Queries in Microsoft Sentinel are custom Kusto Query Language (KQL) queries used by security analysts to proactively search for threats, anomalies, or indicators of compromise within their raw security data.
- Used for proactive threat discovery.
- Explores data for 'unknown unknowns'.
- Can evolve into new analytics rules.
Memory trick: Hunt for Hidden Threats