Creating custom Azure Sentinel Hunting Queries

Creating a hunting query by clicking on Hunting and New Query

Sentinel

Add a name, Description and the custom query.

Sentinel

You can test the query to see that you get the result you’re looking for

Use the mapping to map columns to entities recognized by Azure Sentinel

sentinel

Select tactics for the query

sentinel

The tactics can be used to filter queries



Happy Hunting!

Leave a Comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.