Hunt Threats with KQL and Promote a Hunt to a Detection Rule in Microsoft Sentinel
Run KQL hunting queries against seeded telemetry, save a hunt and bookmark, work the MITRE view, then promote a hunt to a scheduled rule.

Lab overview
Proactive threat hunting is the discipline of seeking out malicious activity that has slipped past automated detections. Instead of waiting for an alert, a hunter forms a hypothesis - "an attacker is brute-forcing sign-ins from a foreign IP" - expresses it as a KQL query, and sweeps historical telemetry for evidence. Microsoft Sentinel turns this into a repeatable workflow: hunters run library and custom hunting queries, bookmark the exact rows that confirm a finding, organize their work around MITRE ATT&CK to expose coverage gaps, and convert a hunt that proves valuable into a standing scheduled analytics rule so the SOC never has to hunt that pattern manually again.
In this lab, you will work in a Microsoft Sentinel workspace pre-seeded with realistic sign-in telemetry. You will explore the seeded data with KQL, save a custom hunting query mapped to a MITRE technique, bookmark a suspicious finding, promote your hunting query into a scheduled analytics rule using the Sentinel wizard, and use the MITRE ATT&CK view to confirm your new hunt and detection improve technique coverage.
Objectives
Upon completion of this advanced level lab, you will be able to:
- Explore pre-seeded sign-in telemetry in Log Analytics with exploratory KQL
- Author and save a custom KQL hunting query mapped to a MITRE ATT&CK technique
- Bookmark a suspicious finding to preserve the row, query, and entity context
- Promote a successful hunting query into a scheduled analytics rule
- Use the MITRE ATT&CK view to confirm hunting-query and detection coverage of a technique
Who is this lab for?
This lab is designed for:
- SOC analysts practicing the proactive hunt-to-detection lifecycle
- Threat hunters who know basic KQL and Sentinel navigation
- Security engineers mapping detection coverage to MITRE ATT&CK
Verified against your live environment
An automated validation engine inspects your actual resources and configurations as you work. Completion means the task was performed, not multiple choice, real-world proficiency.
More labs like this
Hunt for Living-off-the-Land Attacks with KQL in Microsoft Sentinel
Write KQL hunting queries in Microsoft Sentinel to detect living-off-the-land attacks including encoded PowerShell and suspicious WMI activity.
Implement Network Security Groups (NSGs) and Application Security Groups (ASGs) in Azure
Secure Azure VMs using Network Security Groups and Application Security Groups. Create rules, control traffic flow, and implement least privilege access.
Manage Sentinel Detection-as-Code with Terraform
Manage Sentinel analytics rules, an automation rule, and a watchlist as version-controlled Terraform, then make a drift-free change and re-apply.
Environment
Every lab includes
- Real environment, pre-credentialed
- Automated checks on every step
- Isolated sandbox, auto cleanup
- AI-recommended next steps
Lab curriculum
- 01
Logging into Azure CLI
- 02
Explore the Seeded Sign-in Telemetry With KQL
1 automated check
- 03
Author and Save a Custom KQL Hunting Query
1 automated check
- 04
Bookmark a Suspicious Hunting Finding in the Portal
1 automated check
- 05
Promote the Hunting Query to a Scheduled Detection Rule
1 automated check
- 06
Confirm Technique Coverage in the MITRE ATT and CK View
1 automated check
Skills validated
Not the lab you were looking for?
Browse 200+ hands-on labs across AWS, Azure, Kubernetes, Docker, and cloud security.