Concept and mechanism
Hunting starts with a hypothesis that available data can examine. Define the behavior sought, population, time window, sources, and signals that would support or weaken it. Do not confuse no results with no threat, especially when collection has gaps. A query completing without error only proves execution, not completeness of every necessary source. Use results to adjust the hypothesis, seek context, or open an investigation. Correlation should preserve actual entity identity; repeated names across tenants can create false relationships. More rows and a longer search period do not correct a semantically wrong key.
Guided application
Bookmarks help retain findings with queries, relevant results, and notes. Add the window, interpretation, limits, and investigation linkage so another shift can continue. Do not assume saving a bookmark makes every original dataset’s retention unlimited. In the MITRE matrix, distinguish available templates, active rules, and capability validated with required sources. A marked technique does not prove complete operational detection. In a fictional project, turn a repeatable finding into a detection proposal with an owner, tests, noise criteria, and an expected response. Hand RUN a maintainable rule with documentation and dependencies. Preserve the original hypothesis and decision rationale for later coverage reviews.
A template exists but its data source is missing: there is potential coverage work, not proven detection.
Common pitfalls
Empty query as absent threat; name as global ID; bookmark as unlimited retention; matrix as guarantee.
Related topics: SOC platform: data and protection · Investigating across Microsoft services
Preserve hypotheses, evidence, and limits so investigation can continue.
Reference: Threat hunting · SC-200 objectives effective 2026-07-28; Microsoft product documentation reviewed 2026-10-01; 2026-10-21 English update compared separately