Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
08Perform threat hunting in Microsoft Sentinel4 modules · 25 units · Hunting hypotheses, queries, bookmarks, livestream, search jobs, restored logs, and notebooks0/25 units complete
Learning path 08 · Perform threat hunting in Microsoft Sentinel

4 modules · 25 units · Hunting hypotheses, queries, bookmarks, livestream, search jobs, restored logs, and notebooks

0%

Study focus

Hunting workflow

Develop hypotheses, manage hunting queries, preserve evidence with bookmarks, and monitor activity with livestream.

Deep investigation

Use search and restore jobs, notebooks, MSTICPy, APIs, and machine learning for advanced hunts.

4 modules · 25 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

02

Module 2

Threat hunting with Microsoft Sentinel

Focus: hunting-query management, bookmarks, entity pivots, livestream, and the practical hunt workflow.
0/7
01 / 07Introduction

Sentinel hunting combines reusable KQL queries with bookmarks and livestream. Queries find candidates, bookmarks preserve evidence and context, and livestream continuously watches a query for new matching activity.

Official moduleHunting tool objectives
02 / 07Exercise setup

Deploy the Sentinel exercise environment, connect the required telemetry, and verify records before beginning the hunt. Preserve the resources until the final exercise and remove them afterward if they are no longer needed.

Official exercisePrepare hunting telemetry
03 / 07Explore creation and management of threat-hunting queries

The Hunting page includes Microsoft-authored and custom queries. Filter by data source, tactic, technique, result count, or favorite state; run selected queries across a defined time range and inspect results.

A custom hunting query should include a clear name, description, KQL, tactics, techniques, and entity mappings. Map output columns so findings can pivot into entity pages, bookmarks, and investigations.

Official lessonCreate and manage hunting queries
04 / 07Save key findings with bookmarks

A bookmark preserves selected query rows, the query, time range, mapped entities, notes, and tags. Use it to record evidence, group related findings, return to a pivot, or promote findings into an incident.

Bookmarks are snapshots of investigation context; they do not continuously refresh as source data changes.

Official lessonPreserve and promote findings
05 / 07Observe threats over time with livestream

Livestream runs a hunting query continuously and notifies the analyst when new matches appear. Use it for short-lived monitoring during an active investigation or while validating a behavior-based hypothesis.

Optimize the query before starting livestream, use an appropriate lookback, avoid duplicates, and stop sessions that are no longer required.

Official lessonContinuous query monitoring
06 / 07Exercise - Hunt for threats by using Microsoft Sentinel

Run and refine hunting queries, investigate suspicious results, create bookmarks with mapped entities and notes, review them in the investigation experience, and start livestream for ongoing observation.

Official exerciseQuery, bookmark, and livestream
07 / 07Summary

Use hunting queries to discover evidence, bookmarks to preserve and share it, and livestream to watch for recurrence. Convert repeatable high-value logic into analytics rules.

Official moduleSummary and assessment
End of learning pathPerform threat hunting in Microsoft Sentinel