If you’re new to advanced hunting in Microsoft 365 Defender, be sure to check out the four-part series Tali Ash and I presented in July of 2020. We start with the very basics of Kusto Query Language (KQL) and take you all the way to performing visualizations, performing anomaly detection, and track malicious activity purely through advanced hunting.
All of the content is 100% demo, and the heavily commented query files are available on GitHub here for practice in your own tenant. Happy hunting!