Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
08Perform threat hunting in Microsoft Sentinel4 modules · 25 units · Hunting hypotheses, queries, bookmarks, livestream, search jobs, restored logs, and notebooks0/25 units complete
Learning path 08 · Perform threat hunting in Microsoft Sentinel

4 modules · 25 units · Hunting hypotheses, queries, bookmarks, livestream, search jobs, restored logs, and notebooks

0%

Study focus

Hunting workflow

Develop hypotheses, manage hunting queries, preserve evidence with bookmarks, and monitor activity with livestream.

Deep investigation

Use search and restore jobs, notebooks, MSTICPy, APIs, and machine learning for advanced hunts.

4 modules · 25 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

03

Module 3

Use Search jobs in Microsoft Sentinel

Focus: asynchronous searches over long periods, search-result tables, archived data, and restore jobs.
0/5
01 / 05Introduction

Search jobs scan large datasets and long time ranges asynchronously when interactive queries are impractical. Restored logs make a selected historical slice available for high-performance interactive analysis.

Official lessonHistorical-search objectives
02 / 05Hunt with a Search Job

Define the source table, time range, and KQL filter, then start the job and monitor status. Results are written to a new table whose name begins with SearchResults_; the table includes the original records plus search metadata.

Search jobs suit targeted retrieval from Basic or Analytics logs across long retention. Narrow time and predicates to control duration and scan volume.

Official lessonRun and inspect search jobs
03 / 05Restore historical data

A restore job materializes a specified time range from archived Analytics logs into a restored table, enabling full KQL and high-performance queries during an investigation. It restores a time slice rather than filtered rows, so estimate volume carefully.

Restored data is temporary and billable. Query it, export or preserve required evidence, then delete the restored table when work is complete.

Official lessonRestore archived Analytics logs
04 / 05Module assessment

Review search-job use cases, asynchronous execution, SearchResults_ tables, supported log plans, search versus restore, restored-table lifecycle, time ranges, cost, and cleanup.

Official assessmentHistorical data knowledge check
05 / 05Summary and resources

Use a search job for targeted asynchronous retrieval and a restore job when a historical time slice needs interactive, full-KQL investigation.

Official moduleSummary and resources
End of learning pathPerform threat hunting in Microsoft Sentinel