Skip to content

Commit a89cd52

Browse files
authored
Merge pull request #5854 from sbreingold-ms/wi-502580-batch-1-part-c-defender-xdr-image-reorg
wi-502580-batch-1-part-c-defender-xdr-image-reorg
2 parents 487c6fa + 6668455 commit a89cd52

21 files changed

+20
-20
lines changed

defender-xdr/advanced-hunting-query-builder.md

Lines changed: 20 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -44,15 +44,15 @@ You can watch this video to get an overview of guided hunting:
4444

4545
In the **Advanced hunting** page, select **Create new** to open a new query tab and select **Query in builder**.
4646

47-
![Screenshot of guided mode query builder](/defender/media/guided-hunting/01-open-query-builder.png)
47+
![Screenshot of guided mode query builder](media/advanced-hunting-query-builder/01-open-query-builder.png)
4848

4949
This brings you to the guided mode, where you can then construct your query by selecting different components using dropdown menus.
5050

5151
## Specify the data domain to hunt in
5252

5353
You can control the scope of the hunt by selecting which domain the query covers:
5454

55-
![Screenshot of guided mode query builder domains dropdown](/defender/media/guided-hunting/02-specify-domain.png)
55+
![Screenshot of guided mode query builder domains dropdown](media/advanced-hunting-query-builder/02-specify-domain.png)
5656

5757
Selecting **All** includes data from all domains you currently have access to. Narrowing down to a specific domain allows filters relevant to that domain only.
5858

@@ -69,11 +69,11 @@ You can choose from:
6969

7070
By default, guided hunting includes a few basic filters to get you started fast.
7171

72-
![Screenshot of guided mode query builder basic filter set](/defender/media/guided-hunting/03-use-basic-filters.png)
72+
![Screenshot of guided mode query builder basic filter set](media/advanced-hunting-query-builder/03-use-basic-filters.png)
7373

7474
When you choose one data source, for instance, **Endpoints**, the query builder displays only the applicable filter groups. You can then choose a filter you are interested in narrowing down by selecting that filter group, for instance, **EventType**, and selecting the filter of your choice.
7575

76-
![Screenshot of guided mode query builder endpoint basic filter set](/defender/media/guided-hunting/03a-use-basic-filters.png)
76+
![Screenshot of guided mode query builder endpoint basic filter set](media/advanced-hunting-query-builder/03a-use-basic-filters.png)
7777

7878
Once the query is ready, select the blue **Run query** button. If the button is grayed out, it means the query needs to be filled out or edited further.
7979

@@ -83,18 +83,18 @@ Once the query is ready, select the blue **Run query** button. If the button is
8383
## Load sample queries
8484

8585
Another quick way to get familiar with guided hunting is to load sample queries using the **Load sample queries** dropdown menu.
86-
![Screenshot of guided mode query builder load sample queries list](/defender/media/guided-hunting/05-load-sample-queries.png)
86+
![Screenshot of guided mode query builder load sample queries list](media/advanced-hunting-query-builder/05-load-sample-queries.png)
8787

8888
> [!NOTE]
8989
> Selecting a sample query overrides the existing query.
9090
9191
Once the sample query is loaded, select **Run query**.
9292

93-
![Screenshot of guided mode query builder loaded query](/defender/media/guided-hunting/06-load-sample-queries.png)
93+
![Screenshot of guided mode query builder loaded query](media/advanced-hunting-query-builder/06-load-sample-queries.png)
9494

9595
If you have previously selected a domain, the list of available sample queries changes accordingly.
9696

97-
![Screenshot of guided mode query builder restricted list](/defender/media/guided-hunting/07-load-sample-queries.png)
97+
![Screenshot of guided mode query builder restricted list](media/advanced-hunting-query-builder/07-load-sample-queries.png)
9898

9999
To restore the complete list of sample queries, select **All domains** then reopen **Load sample queries**.
100100

@@ -104,17 +104,17 @@ If the loaded sample query uses filters outside of the basic filter set, the tog
104104

105105
To view more filter groups and conditions, select **Toggle to see more filters and conditions**.
106106

107-
![Screenshot of guided mode query builder more filters toggle](/defender/media/guided-hunting/08-use-more-filters.png)
107+
![Screenshot of guided mode query builder more filters toggle](media/advanced-hunting-query-builder/08-use-more-filters.png)
108108

109109
When the **All filters** toggle is active, you can now use the full range of filters and conditions in guided mode.
110110

111-
![Screenshot of guided mode query builder all filters active](/defender/media/guided-hunting/09-use-more-filters.png)
111+
![Screenshot of guided mode query builder all filters active](media/advanced-hunting-query-builder/09-use-more-filters.png)
112112

113113
### Create conditions
114114

115115
To specify a set of data to be used in the query, select **Select a filter**. Explore the different filter sections to find what is available to you.
116116

117-
![Screenshot showing different filters you can use](/defender/media/guided-hunting/10-create-conditions.png)
117+
![Screenshot showing different filters you can use](media/advanced-hunting-query-builder/10-create-conditions.png)
118118

119119
Type the section's titles in the search box at the top of the list to find the filter. Sections ending in *info* contain filters that provide information about the different components you can look at and filters for the states of entities. Sections ending in *events* contain filters that allow you to look for any monitored event on the entity. For instance, to hunt for activities involving certain devices, you can use the filters under the **Device events** section.
120120

@@ -123,11 +123,11 @@ Type the section's titles in the search box at the top of the list to find the f
123123
124124
Next, set the appropriate condition to further filter the data by selecting it from the second dropdown menu and providing entries in the third dropdown menu if necessary:
125125

126-
![Screenshot showing different conditions you can use](/defender/media/guided-hunting/11-create-conditions.png)
126+
![Screenshot showing different conditions you can use](media/advanced-hunting-query-builder/11-create-conditions.png)
127127

128128
You can add more conditions to your query by using **AND**, and **OR** conditions. AND returns results that fulfill all conditions in the query, while OR returns results that fulfill any of the conditions in the query.
129129

130-
![Screenshot showing AND OR operators](/defender/media/guided-hunting/12-create-conditions.png)
130+
![Screenshot showing AND OR operators](media/advanced-hunting-query-builder/12-create-conditions.png)
131131

132132
Refining your query allows you to automatically sift through voluminous records to generate a list of results that is already targeted to your specific threat hunting need.
133133

@@ -139,7 +139,7 @@ Another way to get familiar with guided hunting is to load sample queries pre-cr
139139

140140
In the **Getting started** section of the hunting page, we have provided three guided query examples that you can load. The query examples contain some of the most common filters and inputs you would typically need in your hunting. Loading any of the three sample queries opens a guided tour of how you would construct the entry using guided mode.
141141

142-
![Screenshot of guided mode query builder getting started query walkthroughs](/defender/media/guided-hunting/13-try-sample-query-walkthroughs.png)
142+
![Screenshot of guided mode query builder getting started query walkthroughs](media/advanced-hunting-query-builder/13-try-sample-query-walkthroughs.png)
143143

144144
Follow the instructions in the blue teaching bubbles to construct your query. Select **Run query**.
145145

@@ -149,33 +149,33 @@ Follow the instructions in the blue teaching bubbles to construct your query. Se
149149

150150
To hunt for successful network communications to a specific IP address, start typing "ip" to get suggested filters:
151151

152-
![Screenshot of guided mode query builder hunt for successful connections to specific IP first filter](/defender/media/guided-hunting/14-hunt-for-ips.png)
152+
![Screenshot of guided mode query builder hunt for successful connections to specific IP first filter](media/advanced-hunting-query-builder/14-hunt-for-ips.png)
153153

154154
To look for events involving a specific IP address where the IP is the destination of the communication, select `DestinationIPAddress` under the IP Address Events section. Then select the **equals** operator. Type the IP in the third dropdown menu and press **Enter**:
155155

156-
![Screenshot of guided mode query builder hunt for successful connections to specific IP](/defender/media/guided-hunting/15-hunt-for-ips.png)
156+
![Screenshot of guided mode query builder hunt for successful connections to specific IP](media/advanced-hunting-query-builder/15-hunt-for-ips.png)
157157

158158
Then, to add a second condition which searches for successful network communication events, search for the filter of a specific event type:
159159

160-
![Screenshot of guided mode query builder hunt for successful connections to specific IP, second condition](/defender/media/guided-hunting/16-hunt-for-ips.png)
160+
![Screenshot of guided mode query builder hunt for successful connections to specific IP, second condition](media/advanced-hunting-query-builder/16-hunt-for-ips.png)
161161

162162
The **EventType** filter looks for the different event types logged. It is equivalent to the **ActionType** column which exists in most of the tables in advanced hunting. Select it to choose one or more event types to filter for. To look for successful network communication events, expand the **DeviceNetworkEvents** section and then choose `ConnectionSuccess`:
163163

164-
![Screenshot of guided mode query builder hunt for successful connections to specific IP third condition](/defender/media/guided-hunting/17-hunt-for-ips.png)
164+
![Screenshot of guided mode query builder hunt for successful connections to specific IP third condition](media/advanced-hunting-query-builder/17-hunt-for-ips.png)
165165

166166
Finally, select **Run query** to hunt for all successful network communications to the 52.168.117.170 IP address:
167167

168-
![Screenshot of guided mode query builder hunt for successful connections to specific IP results view](/defender/media/guided-hunting/18-hunt-for-ips.png)
168+
![Screenshot of guided mode query builder hunt for successful connections to specific IP results view](media/advanced-hunting-query-builder/18-hunt-for-ips.png)
169169

170170
### Hunt for high confidence phish or spam emails delivered to inbox
171171

172172
To look for all high confidence phish and spam emails that were delivered to the inbox folder at the time of delivery, first select **ConfidenceLevel** under Email Events, select **equals** and choose **High** under both **Phish** and **Spam** from the suggested closed list which supports multi-selection:
173173

174-
![Screenshot of guided mode query builder hunt high confidence phish or spam emails delivered to inbox, first condition](/defender/media/guided-hunting/19-hunt-for-phish.png)
174+
![Screenshot of guided mode query builder hunt high confidence phish or spam emails delivered to inbox, first condition](media/advanced-hunting-query-builder/19-hunt-for-phish.png)
175175

176176
Then, add another condition, this time specifying the folder or **DeliveryLocation, Inbox/folder**.
177177

178-
![Screenshot of guided mode query builder hunt high confidence phish or spam emails delivered to inbox, second condition](/defender/media/guided-hunting/20-hunt-for-phish.png)
178+
![Screenshot of guided mode query builder hunt high confidence phish or spam emails delivered to inbox, second condition](media/advanced-hunting-query-builder/20-hunt-for-phish.png)
179179

180180
## See also
181181

defender/media/guided-hunting/01-open-query-builder.png renamed to defender-xdr/media/advanced-hunting-query-builder/01-open-query-builder.png

File renamed without changes.

defender/media/guided-hunting/02-specify-domain.png renamed to defender-xdr/media/advanced-hunting-query-builder/02-specify-domain.png

File renamed without changes.

defender/media/guided-hunting/03-use-basic-filters.png renamed to defender-xdr/media/advanced-hunting-query-builder/03-use-basic-filters.png

File renamed without changes.

defender/media/guided-hunting/03a-use-basic-filters.png renamed to defender-xdr/media/advanced-hunting-query-builder/03a-use-basic-filters.png

File renamed without changes.

defender/media/guided-hunting/05-load-sample-queries.png renamed to defender-xdr/media/advanced-hunting-query-builder/05-load-sample-queries.png

File renamed without changes.

defender/media/guided-hunting/06-load-sample-queries.png renamed to defender-xdr/media/advanced-hunting-query-builder/06-load-sample-queries.png

File renamed without changes.

defender/media/guided-hunting/07-load-sample-queries.png renamed to defender-xdr/media/advanced-hunting-query-builder/07-load-sample-queries.png

File renamed without changes.

defender/media/guided-hunting/08-use-more-filters.png renamed to defender-xdr/media/advanced-hunting-query-builder/08-use-more-filters.png

File renamed without changes.

defender/media/guided-hunting/09-use-more-filters.png renamed to defender-xdr/media/advanced-hunting-query-builder/09-use-more-filters.png

File renamed without changes.

0 commit comments

Comments
 (0)