You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-vulnerability-management/defender-vulnerability-management-trial.md
+1-5Lines changed: 1 addition & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,7 +14,7 @@ ms.collection:
14
14
- Tier1
15
15
ms.topic: conceptual
16
16
search.appverid: met150
17
-
ms.date: 04/02/2024
17
+
ms.date: 10/22/2024
18
18
---
19
19
20
20
# About the Microsoft Defender Vulnerability Management trial
@@ -68,10 +68,6 @@ As a Global Administrator, you can start the trial or you can allow to users sta
68
68
69
69
It can take a few hours for the changes to take effect. Once it does, return to the trial setup page and select **Begin trial**.
70
70
71
-
## Licensing
72
-
73
-
As part of the trial setup, the new Defender Vulnerability Management trial licenses will be applied to users automatically. Therefore, no assignment is needed (_The trial can automatically apply up to 1,000,000 licenses_). The licenses are active for the duration of the trial.
74
-
75
71
## Getting started, extending, and ending the trial
Copy file name to clipboardExpand all lines: defender-xdr/advanced-hunting-microsoft-defender.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,12 +22,12 @@ ms.topic: conceptual
22
22
appliesto:
23
23
- Microsoft Defender XDR
24
24
- Microsoft Sentinel in the Microsoft Defender portal
25
-
ms.date: 08/26/2024
25
+
ms.date: 10/18/2024
26
26
---
27
27
28
28
# Advanced hunting in the Microsoft Defender portal
29
29
30
-
Advanced hunting in the unified portal allows you to view and query all data from Microsoft Defender XDR. This includes data from various Microsoft security services and Microsoft Sentinel, which includes data from non-Microsoft products, in a single platform. You can also access and use all your existing Microsoft Sentinel workspace content, including queries and functions.
30
+
Advanced hunting allows you to view and query all the data sources available within the Micrsoft Defender portal. The data sources might include Microsoft Defender XDR and various Microsoft security services. If you onboard Microsoft Sentinel to the Defender portal, access and use all your existing Microsoft Sentinel workspace content, including queries and functions.
31
31
32
32
Querying from a single portal across different data sets makes hunting more efficient and removes the need for context-switching.
Copy file name to clipboardExpand all lines: defender-xdr/advanced-hunting-modes.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,7 +19,7 @@ ms.custom:
19
19
- seo-marvel-apr2020
20
20
ms.topic: how-to
21
21
search.appverid: met150
22
-
ms.date: 04/22/2024
22
+
ms.date: 10/18/2024
23
23
---
24
24
25
25
# Choose between guided and advanced modes to hunt in Microsoft Defender XDR
@@ -29,7 +29,7 @@ ms.date: 04/22/2024
29
29
**Applies to:**
30
30
- Microsoft Defender XDR
31
31
32
-
You can find the **advanced hunting** page by going to the left navigation bar in Microsoft Defender XDR and selecting **Hunting** > **Advanced hunting**. If the navigation bar is collapsed, select the hunting icon .
32
+
You can find the **advanced hunting** page by going to the left navigation bar in the Microsoft Defender portal and selecting **Hunting** > **Advanced hunting**. If the navigation bar is collapsed, select the hunting icon .
33
33
34
34
In the **advanced hunting** page, two modes are supported:
Advanced hunting is a query-based threat hunting tool that lets you explore up to 30 days of raw data. You can proactively inspect events in your network to locate threat indicators and entities. The flexible access to data enables unconstrained hunting for both known and potential threats.
34
34
35
35
Advanced hunting supports two modes, guided and advanced. Use [guided mode](advanced-hunting-query-builder.md) if you are not yet familiar with Kusto Query Language (KQL) or prefer the convenience of a query builder. Use [advanced mode](advanced-hunting-query-language.md) if you are comfortable using KQL to create queries from scratch.
36
36
37
-
**To start hunting, read [Choose between guided and advanced modes to hunt in Microsoft Defender XDR](advanced-hunting-modes.md).**
37
+
**To start hunting, read [Choose between guided and advanced modes to hunt in the Microsoft Defender portal](advanced-hunting-modes.md).**
@@ -46,8 +46,9 @@ Advanced hunting supports queries that check a broader data set coming from:
46
46
- Microsoft Defender for Office 365
47
47
- Microsoft Defender for Cloud Apps
48
48
- Microsoft Defender for Identity
49
+
- Microsoft Sentinel
49
50
50
-
To use advanced hunting, [turn on Microsoft Defender XDR](m365d-enable.md).
51
+
To use advanced hunting, [turn on Microsoft Defender XDR](m365d-enable.md). Or to use advanced hunting with Microsoft Sentinel, [connect Microsoft Sentinel to the Defender portal](microsoft-sentinel-onboard.md).
51
52
52
53
53
54
For more information on advanced hunting in Microsoft Defender for Cloud Apps data, see the [video](https://www.microsoft.com/en-us/videoplayer/embed/RWFISa).
@@ -56,10 +56,12 @@ Selecting **All** includes data from all domains you currently have access to. N
56
56
57
57
You can choose from:
58
58
59
-
- All domains - to look through all available data in your query
60
-
- Endpoints - to look through endpoint data as provided by Microsoft Defender for Endpoint
61
-
- Apps and identities - to look through application and identity data as provided by Microsoft Defender for Cloud Apps and Microsoft Defender for Identity; users familiar with [Activity log](/defender-cloud-apps/activity-filters) can find the same data here
62
-
- Email and collaboration - to look through email and collaboration apps data like SharePoint, OneDrive and others; users familiar with [Threat Explorer](/defender-office-365/threat-explorer-real-time-detections-about) can find the same data here
59
+
- All domains - To look through all available data in your query.
60
+
- Endpoints - To look through endpoint data as provided by Microsoft Defender for Endpoint.
61
+
- Email and collaboration - To look through email and collaboration apps data like SharePoint, OneDrive and others; users familiar with [Threat Explorer](/defender-office-365/threat-explorer-real-time-detections-about) can find the same data here.
62
+
- Apps and identities - To look through application and identity data as provided by Microsoft Defender for Cloud Apps and Microsoft Defender for Identity; users familiar with [Activity log](/defender-cloud-apps/activity-filters) can find the same data here.
63
+
- Cloud infrastructure - To look through cloud infrastructure data as provided by Microsoft Defender for Cloud.
64
+
- Exposure management - To look through exposure management data as provided by Microsoft Security Exposure Management.
63
65
64
66
## Use basic filters
65
67
@@ -177,5 +179,5 @@ Then, add another condition, this time specifying the folder or **DeliveryLocati
177
179
178
180
-[Refine your query in guided mode](advanced-hunting-query-builder-details.md)
179
181
-[Work with query results in guided mode](advanced-hunting-query-builder-results.md)
180
-
-[Understand the schema](advanced-hunting-schema-tables.md)
182
+
-[Understand the schema](advanced-hunting-schema-tables.md)
Advanced hunting is based on the [Kusto query language](/azure/kusto/query/). You can use Kusto operators and statements to construct queries that locate information in a specialized [schema](advanced-hunting-schema-tables.md).
33
32
34
33
Watch this short video to learn some handy Kusto query language basics.
@@ -176,15 +175,15 @@ You can use the query editor to experiment with multiple queries. To use multipl
176
175
- Separate each query with an empty line.
177
176
- Place the cursor on any part of a query to select that query before running it. This will run only the selected query. To run another query, move the cursor accordingly and select **Run query**.
178
177
179
-
:::image type="content" source="/defender/media/multiple-queries.png" alt-text="An example of multiple queries execution in the **New query** page in the Microsoft Defender portal" lightbox="/defender/media/multiple-queries.png":::
178
+
:::image type="content" source="/defender/media/multiple-queries.png" alt-text="An example of multiple queries execution in the **New query** page in the Microsoft Defender portal" lightbox="/defender/media/multiple-queries.png":::
180
179
181
-
For a more efficient workspace, you can also use multiple tabs in the same hunting page. Select **New query** to open a tab for your new query.
180
+
For a more efficient workspace, you can also use multiple tabs in the same hunting page. Select **New query** to open a tab for your new query.
182
181
183
-
:::image type="content" source="/defender/media/multitab.png" alt-text="Opening a new tab by selecting Create new in advanced hunting in the Microsoft Defender portal" lightbox="/defender/media/multitab.png":::
182
+
:::image type="content" source="/defender/media/multitab.png" alt-text="Opening a new tab by selecting Create new in advanced hunting in the Microsoft Defender portal" lightbox="/defender/media/multitab.png":::
184
183
185
-
You can then run different queries without ever opening a new browser tab.
184
+
You can then run different queries without ever opening a new browser tab.
186
185
187
-
:::image type="content" source="/defender/media/multitab-examples.png" alt-text="Run different queries without ever leaving the advanced hunting page in the Microsoft Defender portal" lightbox="/defender/media/multitab-examples.png":::
186
+
:::image type="content" source="/defender/media/multitab-examples.png" alt-text="Run different queries without ever leaving the advanced hunting page in the Microsoft Defender portal" lightbox="/defender/media/multitab-examples.png":::
188
187
189
188
> [!NOTE]
190
189
> Using multiple browser tabs with advanced hunting might cause you to lose your unsaved queries. To prevent this from happening, use the tab feature within advanced hunting instead of separate browser tabs.
While you can construct your [advanced hunting](advanced-hunting-overview.md) queries to return precise information, you can also work with the query results to gain further insight and investigate specific activities and indicators. You can take the following actions on your query results:
Copy file name to clipboardExpand all lines: defender-xdr/advanced-hunting-security-copilot.md
+7-12Lines changed: 7 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,18 +19,14 @@ ms.collection:
19
19
ms.custom:
20
20
- cx-ti
21
21
ms.topic: how-to
22
-
ms.date: 10/02/2024
23
-
---
24
-
25
-
# Microsoft Copilot for Security in advanced hunting
26
-
27
-
28
-
**Applies to:**
29
-
22
+
ms.date: 10/17/2024
23
+
appliesto:
30
24
- Microsoft Defender
31
25
- Microsoft Defender XDR
26
+
- Microsoft Sentinel in the Microsoft Defender portal
27
+
---
32
28
33
-
##Copilot for Security in advanced hunting
29
+
#Microsoft Copilot for Security in advanced hunting
34
30
35
31
[Microsoft Copilot for Security in Microsoft Defender](security-copilot-in-microsoft-365-defender.md) comes with a query assistant capability in advanced hunting.
36
32
@@ -45,7 +41,7 @@ Users with access to Copilot for Security have access to this capability in adva
45
41
46
42
## Try your first request
47
43
48
-
1. Open the **advanced hunting** page from the navigation bar in Microsoft Defender XDR. The Copilot for Security side pane for advanced hunting appears at the right hand side.
44
+
1. Open the **advanced hunting** page from the navigation bar in the Microsoft Defender portal. The Copilot for Security side pane for advanced hunting appears at the right hand side.
49
45
50
46
:::image type="content" source="/defender/media/advanced-hunting-security-copilot-pane.png" alt-text="Screenshot of the Copilot pane in advanced hunting." lightbox="/defender/media/advanced-hunting-security-copilot-pane-big.png":::
51
47
@@ -81,8 +77,7 @@ Users with access to Copilot for Security have access to this capability in adva
81
77
> Providing feedback is an important way to let the Copilot for Security team know how well the query assistant was able to help in generating a useful KQL query. Feel free to articulate what could have made the query better, what adjustments you had to make before running the generated KQL query, or share the KQL query that you eventually used.
82
78
83
79
84
-
> [!NOTE]
85
-
> In the [unified Microsoft Defender portal](advanced-hunting-microsoft-defender.md), you can prompt Copilot for Security to generate advanced hunting queries for both Defender XDR and Microsoft Sentinel tables. Not all Microsoft Sentinel tables are currently supported, but support for these tables can be expected in the future.
80
+
In the [Microsoft Defender portal](advanced-hunting-microsoft-defender.md), you can prompt Copilot for Security to generate advanced hunting queries for both Defender XDR and Microsoft Sentinel tables. Not all Microsoft Sentinel tables are currently supported, but support for these tables can be expected in the future.
[Advanced hunting](advanced-hunting-overview.md) queries can be shared among users in the same organization. You can also save queries that are only accessible to you. You can also find community queries that are shared publicly on GitHub. These saved queries let you quickly pursue specific threat hunting scenarios without having to write queries from scratch.
31
31
32
32
Under the Queries tab in advanced hunting, you can find the drop-down menus for **Shared queries**, **My queries**, and **Community queries**. You can select a downward-facing arrow to expand a menu.
0 commit comments