Skip to content

Commit 9d001df

Browse files
committed
Revise Defender Experts report docs and update images
Expanded and clarified documentation for Defender Experts for Hunting and XDR reports, including new and updated sections, improved instructions, and enhanced descriptions of report features. Added new screenshots and visual assets to illustrate report sections such as hunt trends, emerging threats, hunting summaries, and managed response tasks.
1 parent f712f6c commit 9d001df

10 files changed

+105
-35
lines changed
Lines changed: 50 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
---
2-
title: Understand the Defender Experts for Hunting report in Microsoft Defender XDR
2+
title: Understand the Defender Experts for Hunting report in Microsoft Defender
33
ms.reviewer:
44
description: The Defender Experts for Hunting service publishes reports to help you understand all the threats the hunting service surfaced in your environment
55
search.appverid: met150
66
ms.service: defender-experts-for-hunting
77
f1.keywords:
88
- NOCSH
9-
ms.author: vpattnaik
10-
author: vpattnai
9+
ms.author: pauloliveria
10+
author: poliveria
1111
ms.localizationpriority: medium
12-
manager: dansimp
12+
manager: orspodek
1313
audience: ITPro
1414
ms.custom:
1515
- cx-ti
@@ -19,65 +19,93 @@ ms.collection:
1919
- tier1
2020
- essentials-manage
2121
ms.topic: concept-article
22-
ms.date: 02/07/2025
22+
ms.date: 10/31/2025
2323
---
2424

25-
# Understand the Defender Experts for Hunting report in Microsoft Defender XDR
25+
# Understand the Defender Experts for Hunting report in Microsoft Defender
2626

2727
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2828

2929
**Applies to:**
3030

3131
- [Microsoft Defender XDR](microsoft-365-defender.md)
3232

33-
Microsoft Defender Experts for Hunting layers human intelligence and expert-trained technology to help Microsoft Defender XDR customers understand the significant threats they face. It highlights how Defender Expert's threat hunting skills, thorough understanding of the threat landscape, and knowledge of emerging threats can help you identify, prioritize, and address those threats in your environment.
33+
Microsoft Defender Experts for Hunting combines human intelligence with expert-trained technology to help Microsoft Defender XDR customers understand the significant threats they face. It highlights how Defender Experts' threat hunting skills, thorough understanding of the threat landscape, and knowledge of emerging threats can help you identify, prioritize, and address those threats in your environment.
3434

3535
The Defender Experts for Hunting service generates reports to help you understand all the threats the hunting service surfaced in your environment, alongside the alerts generated by your Microsoft Defender XDR products. You can view the report in the current (running) month, or in one-, three-, or six-month periods.
3636

37-
To view the report in your Microsoft Defender portal, go to **Reports**, select **Defender Experts** > **Defender Experts for Hunting report**. Each section of the report is designed to provide more insights into the threats and suspicious activities our Defender Experts found in your environment.
37+
To view the report in your Microsoft Defender portal, go to **Reports**, select **Defender Experts** > **Hunting report**. Each section of the report is designed to provide more insights into the threats and suspicious activities our Defender Experts found in your environment.
3838

3939
Refer to the following screenshot of a sample report:
4040

4141
:::image type="content" source="media/defender-experts-hunting-report.png" alt-text="Screenshot of Defender Experts for hunting report." lightbox="media/defender-experts-hunting-report.png":::
4242

4343
## Identify prevalent threats and other potential attack entry points
4444

45-
Signals from Microsoft Defender XDR and investigations by Defender Experts for Hunting help identify suspicious activities in your environment. Significant threat activities will have corresponding [Defender Experts Notifications](onboarding-defender-experts-for-hunting.md#receive-defender-experts-notifications), which also provide recommendations to remediate and defend your organization.
45+
Signals from Microsoft Defender XDR and investigations by Defender Experts for Hunting help identify suspicious activities in your environment. Significant threat activities have corresponding [Defender Experts Notifications](onboarding-defender-experts-for-hunting.md#receive-defender-experts-notifications), which also provide recommendations to remediate and defend your organization.
4646

47-
The report provides you with the total number of Defender Experts Notifications our experts have sent for your chosen period:
47+
The top section of the report provides you with the total number of hunts, suspicious threats investigated, and Defender Experts Notifications our experts sent for your chosen period:
4848

4949
:::image type="content" source="media/report-top-section-dens.png" alt-text="Screenshot of the top section of the report showing the number of threats identified." lightbox="media/report-top-section-dens.png":::
5050

51-
To view these notifications, select **View Defender Experts Notifications**. This button redirects you to the Microsoft Defender XDR incidents page. Defender Expert for Hunting alerts or Defender Experts Notifications are labeled with **Defender Experts**.
51+
To view these notifications, select **View Defender Experts Notifications**. This action redirects you to the Microsoft Defender portal **Incidents** page. Defender Experts for Hunting alerts or Defender Experts Notifications have the **Defender Experts** tag.
5252

5353
> [!NOTE]
5454
> The **View Defender Experts Notifications** button only appears if the number of threats identified is at least 1.
5555
56-
All other identified activities are summarized in a table in the **Threat categories** section of the report. The columns represent the different threat attack tactics and categories to help you visualize what an activity is trying to achieve in each attack phase so you can plan the corresponding containment and remediation actions.
56+
All other identified activities are visualized or summarized in the following sections:
57+
- [Hunt trend](#hunt-trend)
58+
- [Emerging threats](#emerging-threats)
59+
- [Hunts by threat category](#hunts-by-threat-category)
60+
61+
### Hunt trend
62+
63+
The **Hunt trend** section displays a trendline chart of the number of hunting activities Defender Experts conducted in your environment for your chosen time period. This chart gives you visibility of the continuous monitoring and investigation our experts are doing even if they don't find any active threats or suspicious activities.
64+
65+
66+
:::image type="content" source="media/hunting-report-hunt-trend.png" alt-text="Screenshot of the Hunt trend section of the Defender Experts for Hunting report." lightbox="media/hunting-report-hunt-trend.png":::
67+
68+
69+
### Emerging threats
70+
71+
The **Emerging threats** section details the proactive, hypothesis-based hunts we conducted in your environment. These hunts focus on tactics that threat actors are just beginning to adopt and other threat intelligence. By surfacing these hunts, we give you visibility into how we're anticipating attacker behavior, validating your defenses against new and notable techniques, and identifying relevant suspicious activity before significant exploitation.
72+
73+
This section is a table that shows the threat title, whether we identified impact in your environment, the threat's severity, and threat category. It aggregates our hunts for emerging threats based on their severity. You can filter this section by the hunts' severity and threat category.
74+
75+
:::image type="content" source="media/hunting-report-emerging-threats.png" alt-text="Screenshot of the Emerging threats section of the Defender Experts for Hunting report." lightbox="media/hunting-report-emerging-threats.png":::
76+
77+
### Hunts by threat category
78+
79+
The **Hunts by threat category** section displays hunting activity tiles that are sorted according to their threat categories. This sorting helps you visualize what an activity is trying to achieve in each attack phase so you can plan the corresponding containment and remediation actions.
80+
81+
:::image type="content" source="/defender/media/defender-experts/threat-categories-filter.png" alt-text="Screenshot of the Hunts by threat category section of the Defender Experts for Hunting report showing the dropdown menu." lightbox="/defender/media/defender-experts/threat-categories-filter.png":::
5782

5883
You can filter the activities displayed in the table by choosing any of the following options in the dropdown menu:
5984

60-
- **Suspicious activities** (default) – Displays identified true positive and benign true positive activities in your environment. Note that not all suspicious activities will have corresponding Defender Expert Notifications.
61-
- **DEX notified** – Displays activities with corresponding Defender Expert Notifications only.
62-
- **All activities** – Displays all true positive, benign true positive, and false positive activities.
85+
- **All** – Displays all true positive, benign true positive, and false positive activities.
86+
- **Suspicious activities** – Displays identified true positive and benign true positive activities in your environment. Not all suspicious activities have corresponding Defender Expert Notifications.
87+
- **Defender Experts Notified** – Displays activities with corresponding Defender Expert Notifications only.
88+
89+
You can also toggle **Show all categories** if you want to display or hide categories that don't have related activities.
6390

64-
:::image type="content" source="/defender/media/defender-experts/threat-categories-filter.png" alt-text="Screenshot of the top section of the Threat categories section showing the dropdown menu." lightbox="/defender/media/defender-experts/threat-categories-filter.png":::
91+
Each activity tile shows the number of hunts Defender Experts conducted related to it. It might also display any of the three icons corresponding to related hunts, [hunting summaries](#hunting-summaries), and Defender Experts Notifications.
6592

66-
If an activity has a related Defender Expert Notification, its corresponding icon also appears under the activity name.
93+
### Hunting summaries
6794

68-
Selecting an identified suspicious activity opens a flyout panel detailing the impacted devices and users:
95+
Each hunt Defender Experts conduct tells a story, even when no active threat is found. In nearly each hunt Defender Experts conduct in your environment, there's a corresponding investigation summary that goes along with it, regardless if we identified a confirmed threat.
6996

70-
:::image type="content" source="media/suspicious-activity-detail-panel.png" alt-text="Screenshot of a flyout panel displaying a list of devices impacted by a detected suspicious activity." lightbox="media/suspicious-activity-detail-panel.png":::
97+
When you select one of the threat titles in the **Emerging threats** section or one of the activity tiles with the scroll icon in the **Hunts by threat category** section, the report opens a side panel that provides a **hunting summary**, or summary of our investigation: what we hunted for, why we hunted for it, and how we reached our final determination. The summary also provides the dates and times the hunt started and concluded, the hunt classification, and impacted assets. If applicable, it also provides links to view related Defender Experts Notifications.
7198

72-
If applicable, the page also provides links to view related Defender Expert Notifications.
99+
:::image type="content" source="media/hunting-report-hunt-summary.png" alt-text="Screenshot of a hunting summary in the Defender Experts for Hunting report." lightbox="media/hunting-report-hunt-summary.png":::
73100

74101
## Know and understand the security weak spots in your environment
75102

76-
The **Top trending suspicious activities** section of the report identifies up to 20 suspicious activities that were consistently observed in your environment in the last three months, sorted based on their severity rating and frequency of occurrence:
103+
The **Top trending suspicious activities** section of the report identifies up to 20 suspicious activities that Defender Experts consistently observed in your environment in the last three months, sorted based on their severity rating and frequency of occurrence:
77104

78105
:::image type="content" source="/defender/media/defender-experts/top-trending-suspicious-activities.png" alt-text="Screenshot of the Top trending suspicious activities section of the report." lightbox="/defender/media/defender-experts/top-trending-suspicious-activities.png":::
79106

80107
By showing the most critical and frequently observed activities, you can assess and evaluate their impact and develop strategies to prevent or mitigate potential threats to your environment
81108

82-
Select **View details** in each card to open a flyout panel detailing the impacted devices and users. If applicable, the page also provides links to view related Defender Expert Notifications.
109+
Select **View details** in each card to open a flyout panel that details the impacted devices and users. If applicable, the page also provides links to view related Defender Expert Notifications.
110+
83111
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/defender-m3d-techcommunity.md)]
-581 KB
Loading
74.6 KB
Loading
168 KB
Loading
32.7 KB
Loading
-138 KB
Loading
41.3 KB
Loading
134 KB
Loading

0 commit comments

Comments
 (0)