Creating custom Azure Sentinel Hunting Queries

Creating a hunting query by clicking on Hunting and New Query


Add a name, Description and the custom query.


You can test the query to see that you get the result you’re looking for

Use the mapping to map columns to entities recognized by Azure Sentinel


Select tactics for the query


The tactics can be used to filter queries

Happy Hunting!

Leave a Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.