Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
08Perform threat hunting in Microsoft Sentinel4 modules · 25 units · Hunting hypotheses, queries, bookmarks, livestream, search jobs, restored logs, and notebooks0/25 units complete
Learning path 08 · Perform threat hunting in Microsoft Sentinel

4 modules · 25 units · Hunting hypotheses, queries, bookmarks, livestream, search jobs, restored logs, and notebooks

0%

Study focus

Hunting workflow

Develop hypotheses, manage hunting queries, preserve evidence with bookmarks, and monitor activity with livestream.

Deep investigation

Use search and restore jobs, notebooks, MSTICPy, APIs, and machine learning for advanced hunts.

4 modules · 25 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

01

Module 1

Explain threat hunting concepts in Microsoft Sentinel

Focus: proactive hunting, the hunting lifecycle, hypotheses, documentation, and MITRE ATT&CK.
0/6
01 / 06Introduction

Threat hunting proactively searches for malicious activity that existing detections have not identified. Sentinel provides the data, KQL, ATT&CK mapping, and hunt-management features needed to turn an idea into repeatable evidence.

Official lessonThreat hunting objectives
02 / 06Understand cybersecurity threat hunts

True proactive hunting begins without a confirmed alert or known-bad indicator and tests a hypothesis about attacker behavior. Indicator searches and incident-driven pivots are still valuable forms of investigation, but they start from known evidence.

HypothesisDefine behavior and scope.
PlanChoose data and tools.
ExecuteQuery and investigate anomalies.
ImproveRespond, document, and create detections.

Record what, why, how, inputs, outputs, replication steps, findings, and next actions—even when the hunt finds no active threat.

Official lessonThe continuous hunting process
03 / 06Develop a hypothesis

A useful hypothesis is achievable with available telemetry and expertise, narrowly scoped, time-bound, efficient, and relevant to the organization's threat model. Start with realistic behaviors and mature incrementally.

Example: accounts executed cmd.exe in the last day although they had not executed it during the preceding week. This states the behavior, comparison, and time window clearly enough to test.

Official lessonBuild a testable hypothesis
04 / 06Explore MITRE ATT&CK

ATT&CK organizes adversary goals as tactics and observed behaviors as techniques and sub-techniques. Use it to translate threat intelligence into hypotheses, identify telemetry requirements, evaluate detection gaps, and communicate coverage consistently.

Technique coverage is not binary: validate whether the relevant data exists, the query detects the intended variation, and the SOC can act on the result.

Official lessonATT&CK-driven hunting
05 / 06Module assessment

Review proactive versus indicator- or incident-driven searches, the hunting lifecycle, documentation, hypothesis quality, threat-model relevance, and ATT&CK tactics and techniques.

Official assessmentHunting concepts knowledge check
06 / 06Summary and resources

A mature hunt is hypothesis-led, evidence-based, repeatable, documented, and converted into detection or monitoring improvements whenever useful.

Official moduleSummary and resources
End of learning pathPerform threat hunting in Microsoft Sentinel