%3CLINGO-SUB%20id%3D%22lingo-sub-1447983%22%20slang%3D%22en-US%22%3ERe%3A%20What%E2%80%99s%20New%3A%20Azure%20Sentinel%20Threat%20Hunting%20Enhancements%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1447983%22%20slang%3D%22en-US%22%3E%3CP%3EGreat%20info%20thanks%3B%20sharing%20on%20LinkedIn%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1433396%22%20slang%3D%22en-US%22%3EWhat%E2%80%99s%20New%3A%20Azure%20Sentinel%20Threat%20Hunting%20Enhancements%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1433396%22%20slang%3D%22en-US%22%3E%3CP%3E%3CEM%3EThis%20blog%20post%20is%20a%20collaboration%20between%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F87823%22%20target%3D%22_blank%22%3E%40Cristhofer%20Munoz%3C%2FA%3E%26nbsp%3Band%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F301871%22%20target%3D%22_blank%22%3E%40Juliango%3C%2FA%3E%26nbsp%3B(Julian%20Gonzalez).%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CEM%3EThis%20installment%20is%20part%20of%20a%20broader%20series%20to%20keep%20you%20up%20to%20date%20with%20the%20latest%20features%2Fenhancements%20in%20Azure%20Sentinel.%20The%20installments%20will%20be%20bite-sized%20to%20enable%20you%20to%20easily%20digest%20the%20new%20content.%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETo%20protect%20against%20the%20current%20threat%20landscape%2C%20security%20operations%20centers%20(SOC)%20require%20a%20robust%20set%20of%20hunting%20capabilities.%26nbsp%3BThreat%20hunting%20is%20an%20iterative%2C%20hypothesis-driven%20process.%20As%20the%20SOC%20analysts%20investigate%20findings%2C%20they%20may%20either%20pivot%20to%20a%20new%20hypothesis%2C%20and%2For%20collect%20additional%20data%20to%20help%20further%20evaluate%20their%20hypothesis.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3ETo%20help%20SOC%20analysts%20proactively%20look%20for%20new%20anomalies%20that%20weren't%20detected%20by%20their%20security%20solutions%2C%20Azure%20Sentinel's%20built-in%20hunting%20capabilities%26nbsp%3Bguide%20you%20into%20asking%20the%20right%20questions%20to%20find%20issues%20in%20the%20data%20you%20already%20have%20on%20your%20network.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20are%20delighted%20to%20introduce%20a%20set%20of%20enhancements%20that%20greatly%20enrich%20the%20analyst%20experience%20with%20Azure%20Sentinel%E2%80%99s%20hunting%20capabilities%20by%20better%20tying%20them%20together%2C%20as%20well%20as%20by%20providing%20prescriptive%20guidance%20on%20best%20practices%20and%20how%20to%20make%20the%20most%20of%20these%20existing%20capabilities.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH3%20id%3D%22toc-hId-1171133016%22%20id%3D%22toc-hId-1171133016%22%3E%3CSTRONG%3EThreat%20Hunting%20Enhancements%3A%3C%2FSTRONG%3E%3C%2FH3%3E%0A%3CUL%3E%0A%3CLI%3EGuides%20%26amp%3B%20Feedback%20Panel%3C%2FLI%3E%0A%3CLI%3EPrescriptive%20guidance%20on%20underlying%20data%3C%2FLI%3E%0A%3CLI%3EGuided%20Tour%3C%2FLI%3E%0A%3CLI%3EColumns%20Chooser%3C%2FLI%3E%0A%3CLI%3EPersistent%20Settings%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH2%20id%3D%22toc-hId-1160629912%22%20id%3D%22toc-hId-1160629912%22%3EGuides%20%26amp%3B%20Feedback%3C%2FH2%3E%0A%3CP%3ETo%20orient%20and%20provide%20prescriptive%20guidance%20on%20how%20to%20maximize%20the%20use%20of%20the%20threat%20hunting%20capabilities%2C%20we%E2%80%99ve%20added%20a%20%E2%80%9CGuides%20%26amp%3B%20Feedback%E2%80%9D%20panel%20to%20%3CSTRONG%3ELivestream%3C%2FSTRONG%3E%20and%20%3CSTRONG%3ENotebooks%20%3C%2FSTRONG%3Eexperiences.%26nbsp%3BThe%20panel%20provides%20rich%20information%20on%20the%20technical%20functionality%20of%20the%20capability%2C%20users%20can%20find%20new%20releases%20and%20updates%20about%20the%20feature%2C%20and%20useful%20links%20to%20best%20practices%2C%20tutorials%2C%20and%20links%20to%20blogs.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20%E2%80%9CGuides%20%26amp%3B%20Feedback%E2%80%9D%20panel%20provides%20the%20opportunity%20to%20share%20your%20ideas%20and%20experience%20with%20our%20core%20engineering%20team%20and%20vote%2Fadd%20your%20ideas%20on%20the%20Azure%20Sentinel%20user%20voice%20platform.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20plan%20to%20expand%20the%20%22Guides%20%26amp%3B%20Feedback%22%20panels%20to%20other%20features%20across%20Azure%20Sentinel%20to%20orient%20and%20provide%20recommended%20practices%20and%20useful%20links%20to%20documentation%2Ftutorials.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22Guides%20%26amp%3B%20Feedback.gif%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F195958i9D83549E579FE225%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Guides%20%26amp%3B%20Feedback.gif%22%20alt%3D%22Guides%20%26amp%3B%20Feedback.gif%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--646824551%22%20id%3D%22toc-hId--646824551%22%3EPrescriptive%20guidance%20on%20underlying%20data%3C%2FH2%3E%0A%3CP%3EData%20is%20the%20foundation%20for%20all%20your%20efforts%20in%20Azure%20Sentinel%2C%20revisiting%20data%20collection%20conversations%20will%20ensure%20that%20you%20have%20the%20necessary%20data%20to%20satisfy%20your%20use%20cases%20in%20Azure%20Sentinel.%26nbsp%3B%20When%20creating%20a%20custom%20hunting%20query%2C%20we%20provide%20prescriptive%20guidance%20on%20the%20underlying%20data%20that%20is%20necessary%20to%20detect%20the%20use%20case%20and%20links%20to%20the%20enable%20the%20appropriate%20data%20connector.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22underlyingdata.gif%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F196264i8E535888DA93980B%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22underlyingdata.gif%22%20alt%3D%22underlyingdata.gif%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1840688282%22%20id%3D%22toc-hId-1840688282%22%3EGuided%20Tour%3C%2FH2%3E%0A%3CP%3EFor%20first-time%20users%20we've%20incorporated%20a%20guided%20tour%20window%20that%20provides%20knowledge%20transfer%20on%20the%20new%20improvements%20added%20to%20the%20hunting%20capabilities.%20We%20will%20expand%20the%20information%20in%20the%20guided%20tours%20to%20provide%20guidelines%20on%20how%20to%20initiate%20your%20proactive%20threat%20hunting%20journey.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22GuidedTour.gif%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F196153iF31FA9A6B5A749C5%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22GuidedTour.gif%22%20alt%3D%22GuidedTour.gif%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22messagebox0-001%22%20class%3D%22fxs-messagebox-title%20msportalfx-tooltip-overflow%22%20data-bind%3D%22%26quot%3Btext%26quot%3B%3Adata.title%2C%26quot%3Bvisible%26quot%3B%3A!data.hideTitle%22%20id%3D%22toc-hId-33233819%22%20id%3D%22toc-hId-33233819%22%3ENew%20Columns%20chooser%3C%2FH2%3E%0A%3CDIV%20class%3D%22fxs-messagebox-template%20css-scope-Microsoft_Azure_Security_Insights%20css-scope-BladesCommonAsiStylecss%20css-scope-BladesSeverityColorscss%20css-scope-BladesCollapsibleControlcss%20css-scope-BladesDetailsControlcss%20css-scope-BladesPropertyControlcss%20css-scope-BladesSummaryGalleryBlockcss%20css-scope-BladesFiltersControlcss%20css-scope-BladesEmptyViewcss%20css-scope-BladesSelectedGridRowsCountControlcss%20css-scope-BladesExtendedEmptyViewcss%20css-scope-BladesMultiLineInfoViewcss%20css-scope-BladesInfoViewcss%20css-scope-BladesDashboardPartcss%20css-scope-BladesGridControlcss%20css-scope-BladesQueryEditorControlcss%20css-scope-BladesMetricsStripControlcss%20css-scope-BladesDataGridcss%20css-scope-BladesHuntingBladecss%22%20data-bind%3D%22%26quot%3BuntrustedHtml%26quot%3B%3A%7B%26quot%3Bhtml%26quot%3B%3Adata.template%2C%26quot%3Bdata%26quot%3B%3Adata.templateViewModel%2C%26quot%3Bisolated%26quot%3B%3Atrue%7D%2C%26quot%3BkeyedCss%26quot%3B%3A%7B%26quot%3BscopingClasses%26quot%3B%3Adata.scopeClass%7D%22%3E%0A%3CDIV%20class%3D%22fxc-base%20fxc-markdown%22%20data-bind%3D%22pcControl%3A%20content%22%20data-formelement%3D%22pcControl%3A%20content%22%3E%0A%3CARTICLE%20class%3D%22fxc-markdown-body%22%20data-bind%3D%22%26quot%3Battr%26quot%3B%3A%7B%26quot%3Baria-disabled%26quot%3B%3A%24ctl._ariaDisabled%2C%26quot%3Baria-label%26quot%3B%3A%24ctl._ariaLabel%7D%22%20aria-disabled%3D%22false%22%3E%0A%3CP%3EThe%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EColumns%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Ebutton%20allows%20users%20to%20personalize%20the%20grid%20by%20selecting%20the%20relevant%20columns%20and%20their%20order.%20This%20enables%20SOC%20analysts%20to%20have%20deep%20flexibility%20and%20control%20over%20the%20grid%20view.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20hunting%20queries%20grid%20offers%203%20new%20columns%3A%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3ECreated%20By%3C%2FSTRONG%3E%2C%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3ECreated%20Time%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eand%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EEntities%3C%2FSTRONG%3E.%3C%2FP%3E%0A%3CP%3EThe%20bookmarks%20grid%20offers%203%20new%20columns%3A%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EUpdated%20By%3C%2FSTRONG%3E%2C%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EUpdated%20Time%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eand%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3ENotes%3C%2FSTRONG%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3C%2FARTICLE%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22columns.gif%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F195949i2E15DF85DCFDE578%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22columns.gif%22%20alt%3D%22columns.gif%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId--1774220644%22%20id%3D%22toc-hId--1774220644%22%3E%26nbsp%3B%3C%2FH2%3E%0A%3CH2%20id%3D%22toc-hId-713292189%22%20id%3D%22toc-hId-713292189%22%3EPersistent%20Settings%3C%2FH2%3E%0A%3CP%3E%3CSPAN%3EAny%20changes%20users%20make%20to%20the%20grid%20are%20now%20persistent%20across%20sessions.%20That%20includes%3A%20columns%20width%2C%20sorting%20orders%20and%20filter.%20This%20enhancement%20will%20impact%20the%20way%20your%20SOC%20Analyst%20across%20Azure%20Sentinel's%20hunting%20capabilities%20by%20saving%20their%20grid%20preferences%2C%20hence%20maximizing%20their%20scarce%20time.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1758710297%22%20id%3D%22toc-hId--1094162274%22%20id%3D%22toc-hId--1094162274%22%3EGet%20started%20today!%3C%2FH2%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20encourage%20you%20to%20leverage%20the%20new%20enhancements%20to%20maximize%20usage%20of%20Azure%20Sentinel%20out%20the%20box%20threat%20hunting%20capabilities.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETry%20it%20out%2C%20and-ERR%3AREF-NOT-FOUND-%26nbsp%3Blet%20us%20know%26nbsp%3Bwhat%20you%20think!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1433396%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22columns.gif%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F195949i2E15DF85DCFDE578%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22columns.gif%22%20alt%3D%22columns.gif%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWe%20are%20delighted%20to%20introduce%20a%20set%20of%20enhancements%20that%20greatly%20enhance%20the%20analyst%20experience%20with%20Azure%20Sentinel%E2%80%99s%20hunting%20capabilities%20by%20better%20tying%20them%20together%2C%20as%20well%20as%20by%20providing%20documentation%20and%20training%20on%20how%20to%20make%20the%20most%20of%20these%20existing%20capabilities.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1433396%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDetection%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHunting%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EInvestigation%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWhat's%20New%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E

This blog post is a collaboration between @Cristhofer Munoz and @JulianGonzalez (Julian Gonzalez).

 

This installment is part of a broader series to keep you up to date with the latest features/enhancements in Azure Sentinel. The installments will be bite-sized to enable you to easily digest the new content.

 

To protect against the current threat landscape, security operations centers (SOC) require a robust set of hunting capabilities. Threat hunting is an iterative, hypothesis-driven process. As the SOC analysts investigate findings, they may either pivot to a new hypothesis, and/or collect additional data to help further evaluate their hypothesis.

 

To help SOC analysts proactively look for new anomalies that weren't detected by their security solutions, Azure Sentinel's built-in hunting capabilities guide you into asking the right questions to find issues in the data you already have on your network.

 

We are delighted to introduce a set of enhancements that greatly enrich the analyst experience with Azure Sentinel’s hunting capabilities by better tying them together, as well as by providing prescriptive guidance on best practices and how to make the most of these existing capabilities.

 

Threat Hunting Enhancements:

  • Guides & Feedback Panel
  • Prescriptive guidance on underlying data
  • Guided Tour
  • Columns Chooser
  • Persistent Settings

Guides & Feedback

To orient and provide prescriptive guidance on how to maximize the use of the threat hunting capabilities, we’ve added a “Guides & Feedback” panel to Livestream and Notebooks experiences. The panel provides rich information on the technical functionality of the capability, users can find new releases and updates about the feature, and useful links to best practices, tutorials, and links to blogs.

 

The “Guides & Feedback” panel provides the opportunity to share your ideas and experience with our core engineering team and vote/add your ideas on the Azure Sentinel user voice platform.

 

We plan to expand the "Guides & Feedback" panels to other features across Azure Sentinel to orient and provide recommended practices and useful links to documentation/tutorials.

 

Guides & Feedback.gif

 

Prescriptive guidance on underlying data

Data is the foundation for all your efforts in Azure Sentinel, revisiting data collection conversations will ensure that you have the necessary data to satisfy your use cases in Azure Sentinel.  When creating a custom hunting query, we provide prescriptive guidance on the underlying data that is necessary to detect the use case and links to the enable the appropriate data connector.

 

underlyingdata.gif

 

Guided Tour

For first-time users we've incorporated a guided tour window that provides knowledge transfer on the new improvements added to the hunting capabilities. We will expand the information in the guided tours to provide guidelines on how to initiate your proactive threat hunting journey.

 

GuidedTour.gif

 

New Columns chooser

The Columns button allows users to personalize the grid by selecting the relevant columns and their order. This enables SOC analysts to have deep flexibility and control over the grid view. 

 

The hunting queries grid offers 3 new columns: Created By, Created Time and Entities.

The bookmarks grid offers 3 new columns: Updated By, Updated Time and Notes.

 

columns.gif

 

Persistent Settings

Any changes users make to the grid are now persistent across sessions. That includes: columns width, sorting orders and filter. This enhancement will impact the way your SOC Analyst across Azure Sentinel's hunting capabilities by saving their grid preferences, hence maximizing their scarce time.

 

Get started today!

 

We encourage you to leverage the new enhancements to maximize usage of Azure Sentinel out the box threat hunting capabilities.

 

Try it out, and let us know what you think!

1 Comment
Occasional Contributor

Great info thanks; sharing on LinkedIn