Tracking the Adversary with M365 Defender Advanced Hunting

If you’re new to advanced hunting in Microsoft 365 Defender, be sure to check out the four-part series Tali Ash and I presented in July of 2020. We start with the very basics of Kusto Query Language (KQL) and take you all the way to performing visualizations, performing anomaly detection, and track malicious activity purely through advanced hunting.

All of the content is 100% demo, and the heavily commented query files are available on GitHub here for practice in your own tenant. Happy hunting!

YouTube player
Episode 1: KQL Fundamentals
YouTube player
Episode 2: Joins
YouTube player
Episode 3: Summarizing, pivoting, and visualizing data
YouTube player
Episode 4: Let’s hunt!

Leave a Reply