← SC-200: investigation and security operations response
10 / 10 · 50 MIN

Hunting with the lake, graphs, and notebooks

Choose search mechanisms and validate results with scope, cost, and provenance.

KQL jobs, summary rules, and search jobs

Choose based on the required operation. KQL jobs run asynchronous queries over the data lake, including investigations across multiple tables; check supported operators and job state. Summary rules periodically aggregate data into result tables. Search jobs retrieve results from one table for further analysis; they do not replace a join between two sources. Before execution, bound the period and columns and estimate analysis cost. A completed job does not establish that its query answered the hypothesis. Inspect results, coverage, and possible failures before using them in a decision.

Aggregation and preservation of detail

A table counting connections per hour supports trend analysis but does not automatically retain every destination IP or request sequence. Define each row’s unit and the fields needed to return to detail. Observe summary-rule health and the covered window: an empty bin may reflect missing data or processing failure. At handover, distinguish event time from when the summary became available. If an analyst must reconstruct a transaction, confirm that underlying detail remains retained and accessible through an appropriate mechanism.

Graphs and potential reach

Sentinel Graph represents entities and relationships. A path between an account and a critical asset helps prioritize investigation and containment. Blast radius describes potential reach; it does not prove the attacker traversed every relationship. Examine link type, data freshness, and effective permissions. For an account with potential access to two services, seek observed activity in each before claiming both compromised. When building a custom graph, define node keys and edge meaning; repeated names and stale relationships can create misleading paths.

Notebooks and access through MCP

Notebooks combine code, results, and investigation notes. In the data lake, confirm onboarding, workspace, permissions, and runtime before running Python/Spark. Preserve parameters and versions needed to reproduce analysis. The Sentinel MCP data exploration collection supports table discovery, queries, and graph tools within permissions. Connecting a client to MCP does not grant it all tenant content. Review generated code, write destinations, and queried volumes before execution. In a hunting prototype, begin with synthetic data or an authorized scope and check that shared outputs omit unnecessary information.

From hypothesis to detection testing

A threat analytics report can suggest behaviors to hunt for; relate them to data you actually hold. Preserve the query, dates, identifiers, relevant results, and limitations. If a graph reveals a suspicious relationship, confirm it through events and context before reaching a definitive conclusion. A repeatable investigation supports a detection proposal with noise and response criteria. For a new rule, define examples that should signal and legitimate examples that should not. The project ends with a team able to interpret failures and adjust the rule when data or operational behavior changes.

IN PRACTICE

A fictional exercise investigates links between historical access and critical assets. The deliverable includes the query, period, sources, limitations, and a justified recommendation.

Common pitfalls

Search job as a join; summary as complete events; possible path as proven intrusion; generated code as approved execution.

Related topics: SOC collection and permissions · Windows, delays, and entities

Take this idea with you

A reproducible investigation explains what it searched for, in which data, and what the result supports.

Create account

Reference: Compare lake KQL jobs, summary rules and search jobs · SC-200 objectives effective 2026-07-28; Microsoft product documentation reviewed 2026-10-01; 2026-10-21 English update compared separately