question

AaronCai-6125 avatar image
0 Votes"
AaronCai-6125 asked TeemoTang-MSFT answered

Can I configure the Microsoft 365 Defender Advcanced hunting by myself?

hi,
I'm trying to find some of about the Advanced hunting in Microsoft 365 Defender. I wanna to know, can I configure or view the information about schema reference?Like some fields, what is its detection principle code? how can i view that, or i can't view that.

windows-10-security
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

TeemoTang-MSFT avatar image
0 Votes"
TeemoTang-MSFT answered

Hi,

To use advanced hunting or other Microsoft 365 Defender capabilities, you need an appropriate role in Azure Active Directory.
Required roles and permissions for advanced hunting.
https://docs.microsoft.com/en-us/microsoft-365/security/defender/custom-roles?view=o365-worldwide
To use advanced hunting, you need to turn on Microsoft 365 Defender.

Reference:
Proactively hunt for threats with advanced hunting in Microsoft 365 Defender
https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-overview?view=o365-worldwide

On the other hand, if you want detection principle code or development related knowledge, you’d better ask for help from github rather than Q&A
GitHub - microsoft/Microsoft-365-Defender-Hunting-Queries: Sample queries for Advanced hunting in Microsoft 365 Defender
https://github.com/microsoft/Microsoft-365-Defender-Hunting-Queries


If the Answer is helpful, please click "Accept Answer" and upvote it.
Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.