Custom detections overview

Applies to:

With custom detections, you can proactively monitor for and respond to various events and system states, including suspected breach activity and misconfigured machines. This is made possible by customizable detection rules that automatically trigger alerts as well as response actions.

Custom detections work with Advanced hunting, which provides a powerful, flexible query language that covers a broad set of event and system information from your network. The queries run every 24 hours, generating alerts and taking response actions whenever there are matches.

Custom detections provide:

  • Alerts for rule-based detections built from Advanced hunting queries
  • Automatic response actions that apply to files and machines


To create and manage custom detections, your role needs to have the manage security settings permission.