You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/hunts.md
+5-3Lines changed: 5 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -55,10 +55,12 @@ Microsoft Sentinel gives you flexibility as you zero in on the right set of hunt
55
55
### Hypothesis - New threat campaign
56
56
Content hub offers threat campaign and domain-based solutions to hunt for specific attacks.
57
57
58
-
1. For example, install the "Log4J Vulnerability Detection" or the "Apache Tomcat" solutions from Microsoft.
58
+
1. For example, install the "Log4J Vulnerability Detection" or the "Apache Tomcat" solutions from Microsoft.
59
+
59
60
:::image type="content" source="media/hunts/content-hub-solutions.png" alt-text="Screenshot shows the content hub in grid view with the Log4J and Apache solutions selected." lightbox="media/hunts/content-hub-solutions.png":::
60
61
61
-
1. Once installed, create a hunt directly from the solution by selecting the package > **Actions** > **Create hunt (preview)**.
62
+
1. Once installed, create a hunt directly from the solution by selecting the package > **Actions** > **Create hunt (Preview)**.
63
+
62
64
:::image type="content" source="media/hunts/add-content-queries-to-hunt.png" alt-text="Screenshot shows action menu options from content hub solutions page.":::
63
65
64
66
1. If you already have a hunt started, select **Add to existing hunt (Preview)** to add the queries from the solution to an existing hunt.
@@ -238,4 +240,4 @@ In this article you learned how to run a hunting investigation with the hunts fe
238
240
For more information, see:
239
241
-[Hunt for threats with Microsoft Sentinel](hunting.md)
240
242
-[Understand Microsoft Sentinel's incident investigation and case management capabilities](incident-investigation.md)
241
-
-[Navigate and investigate incidents](investigate-incidents.md)
243
+
-[Navigate and investigate incidents](investigate-incidents.md)
0 commit comments