Hands-On LabAdvanced

Hunt Threats with KQL and Promote a Hunt to a Detection Rule in Microsoft Sentinel

Run KQL hunting queries against seeded telemetry, save a hunt and bookmark, work the MITRE view, then promote a hunt to a scheduled rule.

70 minEstimated time
6Guided steps
AutoVerification
IsolatedSandbox
Hunt Threats with KQL and Promote a Hunt to a Detection Rule in Microsoft Sentinel

Lab overview

Proactive threat hunting is the discipline of seeking out malicious activity that has slipped past automated detections. Instead of waiting for an alert, a hunter forms a hypothesis - "an attacker is brute-forcing sign-ins from a foreign IP" - expresses it as a KQL query, and sweeps historical telemetry for evidence. Microsoft Sentinel turns this into a repeatable workflow: hunters run library and custom hunting queries, bookmark the exact rows that confirm a finding, organize their work around MITRE ATT&CK to expose coverage gaps, and convert a hunt that proves valuable into a standing scheduled analytics rule so the SOC never has to hunt that pattern manually again.

In this lab, you will work in a Microsoft Sentinel workspace pre-seeded with realistic sign-in telemetry. You will explore the seeded data with KQL, save a custom hunting query mapped to a MITRE technique, bookmark a suspicious finding, promote your hunting query into a scheduled analytics rule using the Sentinel wizard, and use the MITRE ATT&CK view to confirm your new hunt and detection improve technique coverage.

Objectives

Upon completion of this advanced level lab, you will be able to:

  • Explore pre-seeded sign-in telemetry in Log Analytics with exploratory KQL
  • Author and save a custom KQL hunting query mapped to a MITRE ATT&CK technique
  • Bookmark a suspicious finding to preserve the row, query, and entity context
  • Promote a successful hunting query into a scheduled analytics rule
  • Use the MITRE ATT&CK view to confirm hunting-query and detection coverage of a technique

Who is this lab for?

This lab is designed for:

  • SOC analysts practicing the proactive hunt-to-detection lifecycle
  • Threat hunters who know basic KQL and Sentinel navigation
  • Security engineers mapping detection coverage to MITRE ATT&CK

Verified against your live environment

An automated validation engine inspects your actual resources and configurations as you work. Completion means the task was performed, not multiple choice, real-world proficiency.

[CHECK] validation_activelive
Inspecting deployed resources...
Verifying configuration state...
✓ Step requirements satisfied

More labs like this

PremiumIncluded in Premium
Duration
70 min
Steps
6

Environment

Browser Code IDELive Cloud Environment

Every lab includes

  • Real environment, pre-credentialed
  • Automated checks on every step
  • Isolated sandbox, auto cleanup
  • AI-recommended next steps

Lab curriculum

  1. 01

    Logging into Azure CLI

  2. 02

    Explore the Seeded Sign-in Telemetry With KQL

    1 automated check

  3. 03

    Author and Save a Custom KQL Hunting Query

    1 automated check

  4. 04

    Bookmark a Suspicious Hunting Finding in the Portal

    1 automated check

  5. 05

    Promote the Hunting Query to a Scheduled Detection Rule

    1 automated check

  6. 06

    Confirm Technique Coverage in the MITRE ATT and CK View

    1 automated check

Skills validated

Microsoft SentinelKusto Query Language

Not the lab you were looking for?

Browse 200+ hands-on labs across AWS, Azure, Kubernetes, Docker, and cloud security.

Explore the catalog