Microsoft-365-Defender-Hunting-Queries icon indicating copy to clipboard operation
Microsoft-365-Defender-Hunting-Queries copied to clipboard

Sample queries for Advanced hunting in Microsoft 365 Defender

Results 48 Microsoft-365-Defender-Hunting-Queries issues
Sort by recently updated
recently updated
newest added

Can we detect any workstation having persistence drive using any query in defender?

Advance hunting quey to get a Report on Missing KB From All devices.

Hello Team, In our workstations , we have set of applications access from the browser. We want to monitor if any one logged in the respective applications with one particular...

Advanced Hunting Section included legacy table names. Updates only replace the legacy table names (e.g. `AlertEvents`) with their corresponding new names (e.g. `DeviceAlertEvents`). While there are additional tables published since...

Replace old schema reference DeviceAlertEvents with AlertInfo | join AlertEvidence on AlertId

Can you add Health state and Date last seen to the query? I added onto your query but it doesnt work and it also only queries 1 machine and not...

Hello Microsoft Team, Not sure if this is planned already, It would be great to get few queries for a new Web Content Filtering feature. Here are few suggestions: -...