Microsoft Threat Hunting
Master Microsoft Threat Hunting
Go beyond alerts and become a proactive hunter. Learn hypothesis-driven threat hunting across Microsoft 365, Entra ID, Defender XDR, and Sentinel; so you can find stealthy attackers, uncover hidden compromises, and hunt like a professional before threats become breaches.
What you'll be able to do
“Really appreciate how the training broke down and showed us how to find the stuff that matters and create effective trigger points for detections. Writing KQL queries to hunt for mailbox delegation changes and persistence mechanisms gave us a massive practical experience.”
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Hunt Methodology & Advanced Toolcraft
What Microsoft Threat Hunting teaches: run the hypothesis-driven hunt cycle to find the stealthy attacker no alert fired on, across Entra ID, Defender XDR, and Sentinel, through ten complete hunt campaigns, and turn every hunt into a new detection. The hunt cycle you'll run, the campaigns and playbooks you walk away with, and how the course is structured. Start here.
Show 9 lessonsHide lessons
- 0.10.1 The Detection GapPreview
- 0.20.2 Why Detection Engineering Cannot Close the GapPreview
- 0.30.3 The M365 Threat LandscapePreview
- 0.40.4 Where Hunting FitsPreview
- 0.50.5 The Business Case for HuntingPreview
- 0.60.6 Organizational Readiness and Data SourcesPreview
- 0.70.7 The Hunter's Skillset and MaturityPreview
- 0.80.8 Your First 90 DaysPreview
- 0.9Module SummaryPreview
The six-step methodology that every campaign module follows. Hypothesis formulation, scoping, iterative collection, contextual analysis, conclusion documentation, detection rule conversion, the hunt documentation standard, a complete worked example, and operational cadence with quality assurance.
Show 12 lessonsHide lessons
- 1.11.1 Formulating Hunt Hypotheses
- 1.21.2 Scoping the Hunt
- 1.31.3 Collection: Iterative Querying
- 1.41.4 Analysis: Separating Signal from Noise
- 1.51.5 Concluding the Hunt
- 1.61.6 Converting Hunts to Detection Rules
- 1.71.7 The Hunt Documentation Standard
- 1.81.8 The Hunt-to-Detection Pipeline: Worked End-to-End
- 1.91.9 Hunt Cadence and Scheduling
- 1.101.10 Hunt Quality Assurance and Metrics
- 1.11Module Summary
- 1.12Check My Knowledge
The KQL patterns that separate hunting queries from detection rules. Statistical outlier detection, time-series anomaly analysis, behavioral clustering, frequency profiling, entity pivoting, performance optimization, and query debugging. Every operator taught here drives the hunt campaigns in M3 through M13.
Show 13 lessonsHide lessons
- 2.12.1 Troubleshooting and Debugging KQL Queries
- 2.22.2 Percentile and Statistical Deviation for Outlier Detection
- 2.32.3 The make-series Operator
- 2.42.4 series_decompose_anomalies()
- 2.52.5 series_fir() and Time Series Smoothing
- 2.62.6 top-nested for Frequency Analysis
- 2.72.7 autocluster() for Behavioral Grouping
- 2.82.8 arg_max and arg_min for Entity Investigation
- 2.92.9 Dynamic Column Parsing for M365 Logs
- 2.102.10 materialize() and Query Performance
- 2.112.11 Entity Pivoting Across Tables
- 2.12Module Summary
- 2.13Check My Knowledge
Map your current detection rules to MITRE ATT&CK. Identify coverage gaps. Score each gap by threat relevance, data availability, and impact severity. Produce a prioritized hunt backlog, the artifact that drives every campaign module that follows. This is where your hunting program starts producing real output.
Show 17 lessonsHide lessons
- 3.1TH3.1 Exporting Your Analytics Rule Inventory
- 3.2TH3.2 Mapping Rules to MITRE ATT&CK Techniques
- 3.3TH3.3 Visualizing Coverage with ATT&CK Navigator
- 3.4TH3.4 Identifying Coverage Gaps by Tactic
- 3.5TH3.5 Coverage Clustering. Where Rules Concentrate
- 3.6TH3.6 Threat Intelligence–Driven Gap Prioritization
- 3.7TH3.7 Data Availability Scoring
- 3.8TH3.8 Impact Severity Scoring
- 3.9TH3.9 Building the Composite Score Matrix
- 3.10TH3.10 Assembling the Hunt Backlog
- 3.11TH3.11 Selecting Your First Three Campaigns
- 3.12TH3.12 Validating Hypotheses Before Hunting
- 3.13TH3.13 Backlog Maintenance and Quarterly Review
- 3.14TH3.14 Common Coverage Analysis Mistakes
- 3.15TH3.15 From Analysis to Action. Your 90-Day Plan
- 3.16Module Summary
- 3.17Check My Knowledge
Phase 2: Hunt Campaigns
The first campaign module. Six identity attack techniques hunted across interactive and non-interactive sign-in tables: AiTM session hijacking, credential stuffing, password spray, MFA fatigue, custom impossible travel, and session token anomalies. Every query runs against your environment. Every finding is a real security finding in your organization.
Show 17 lessonsHide lessons
- 4.1TH4.1 Building the Authentication Baseline
- 4.2TH4.2 Hunting AiTM Session Hijacking
- 4.3TH4.3 Hunting Credential Stuffing
- 4.4TH4.4 Hunting Password Spray
- 4.5TH4.5 Hunting MFA Fatigue Attacks
- 4.6TH4.6 Hunting MFA Bypass Techniques
- 4.7TH4.7 Building Custom Impossible Travel Detection
- 4.8TH4.8 Session Hijacking via Non-Interactive Tokens
- 4.9TH4.9 Hunting Compromised Service Principals
- 4.10TH4.10 Authentication Anomalies with Time-Series Analysis
- 4.11TH4.11 Correlating Identity Compromise Indicators
- 4.12TH4.12 Building the Identity Hunt Report
- 4.13TH4.13 Converting Identity Hunts to Detection Rules
- 4.14TH4.14 Common Identity Hunting Mistakes
- 4.15TH4.15 Identity Hunt Operational Playbook
- 4.16Module Summary
- 4.17Check My Knowledge
The second campaign module. Seven cloud persistence techniques hunted across CloudAppEvents, AuditLogs, and email tables: inbox rules via Graph API, mail forwarding, OAuth consent persistence, MFA method registration, conditional access manipulation, federated trust abuse, and temporal correlation with initial compromise indicators. Every persistence mechanism found is an attacker who survived your first remediation.
Show 15 lessonsHide lessons
- 5.1TH5.1 The Cloud Persistence Landscape
- 5.2TH5.2 Hunting Inbox Rules Created via Graph API
- 5.3TH5.3 Hunting Mail Forwarding and Redirect Rules
- 5.4TH5.4 Hunting OAuth Consent Persistence
- 5.5TH5.5 Hunting Admin Consent and Tenant-Wide App Access
- 5.6TH5.6 Hunting MFA Method Registration as Persistence
- 5.7TH5.7 Hunting Conditional Access Policy Manipulation
- 5.8TH5.8 Hunting Federated Trust Abuse
- 5.9TH5.9 Temporal Correlation with Initial Compromise
- 5.10TH5.10 Building the Persistence Hunt Report
- 5.11TH5.11 Converting Persistence Hunts to Detection Rules
- 5.12TH5.12 Common Persistence Hunting Mistakes
- 5.13TH5.13 Persistence Hunt Operational Playbook
- 5.14Module Summary
- 5.15Check My Knowledge
The third campaign module. Seven privilege escalation techniques hunted across AuditLogs, PIM logs, and directory change records: direct role assignments outside PIM, Global Admin activation anomalies, emergency access account misuse, service principal credential abuse, admin consent for privilege, security group manipulation, and conditional access weakening for elevated access. Every escalation found is an attacker who moved from user-level access to admin-level control.
Show 15 lessonsHide lessons
- 6.1TH6.1 The Privilege Escalation Landscape
- 6.2TH6.2 Hunting Role Assignments Outside PIM
- 6.3TH6.3 Hunting Global Admin Activation Anomalies
- 6.4TH6.4 Hunting Emergency Access Account Misuse
- 6.5TH6.5 Hunting Service Principal Credential Abuse for Escalation
- 6.6TH6.6 Hunting Admin Consent for Privilege Escalation
- 6.7TH6.7 Hunting Security Group Manipulation
- 6.8TH6.8 Hunting CA Weakening for Elevated Access
- 6.9TH6.9 Temporal Correlation. Escalation Timeline
- 6.10TH6.10 Building the Privilege Escalation Hunt Report
- 6.11TH6.11 Converting to Detection Rules
- 6.12TH6.12 Common Mistakes
- 6.13TH6.13 Privilege Escalation Hunt Operational Playbook
- 6.14Module Summary
- 6.15Check My Knowledge
The fourth campaign module. Seven email threat techniques hunted across EmailEvents, CloudAppEvents, and authentication tables: BEC from compromised internal accounts, internal phishing from legitimate mailboxes, vendor email compromise, mail flow rule manipulation, auto-forwarding to external addresses, financial keyword interception, and email campaign correlation with authentication anomalies.
Show 14 lessonsHide lessons
- 7.1TH7.1 The Email Threat Landscape in M365
- 7.2TH7.2 Hunting BEC from Compromised Internal Accounts
- 7.3TH7.3 Hunting Internal Phishing from Legitimate Mailboxes
- 7.4TH7.4 Hunting Vendor Email Compromise
- 7.5TH7.5 Hunting Mail Flow Rule Manipulation
- 7.6TH7.6 Hunting Financial Keyword Interception
- 7.7TH7.7 Consolidated External Forwarding Audit
- 7.8TH7.8 Email Campaign Correlation with Authentication Anomalies
- 7.9TH7.9 Building the Email Threat Hunt Report
- 7.10TH7.10 Converting to Detection Rules
- 7.11TH7.11 Common Mistakes
- 7.12TH7.12 Email Threat Hunt Operational Playbook
- 7.13Module Summary
- 7.14Check My Knowledge
The fifth campaign module. Six data exfiltration channels hunted across CloudAppEvents, SharePoint audit logs, and device telemetry: SharePoint and OneDrive bulk download anomalies, external sharing link creation, email-based data exfiltration, Teams file exfiltration, browser downloads to unmanaged devices, and multi-channel exfiltration correlation. Every finding represents data leaving your organization, either to an attacker or through an unauthorized channel.
Show 13 lessonsHide lessons
- 8.1TH8.1 The Data Exfiltration Landscape
- 8.2TH8.2 Hunting SharePoint and OneDrive Bulk Downloads
- 8.3TH8.3 Hunting External Sharing Link Creation
- 8.4TH8.4 Hunting Email-Based Data Exfiltration
- 8.5TH8.5 Hunting Teams File Exfiltration
- 8.6TH8.6 Hunting Downloads to Unmanaged Devices
- 8.7TH8.7 Multi-Channel Exfiltration Correlation
- 8.8TH8.8 Building the Data Exfiltration Hunt Report
- 8.9TH8.9 Converting to Detection Rules
- 8.10TH8.10 Common Mistakes
- 8.11TH8.11 Data Exfiltration Hunt Operational Playbook
- 8.12Module Summary
- 8.13Check My Knowledge
The sixth campaign module. Seven endpoint threat techniques hunted across DeviceProcessEvents, DeviceNetworkEvents, DeviceFileEvents, and DeviceRegistryEvents: LOLBin abuse with network connections, process injection indicators, registry and scheduled task persistence, defense evasion (timestomping, log clearing, ASR bypass), C2 beaconing with time-series variance analysis, fileless execution, and process tree analysis.
Show 14 lessonsHide lessons
- 9.1TH9.1 The Endpoint Threat Landscape
- 9.2TH9.2 Hunting LOLBin Abuse with Network Connections
- 9.3TH9.3 Hunting Process Injection Indicators
- 9.4TH9.4 Hunting Registry and Scheduled Task Persistence
- 9.5TH9.5 Hunting Defense Evasion
- 9.6TH9.6 Hunting C2 Beaconing
- 9.7TH9.7 Hunting Fileless Execution
- 9.8TH9.8 Process Tree Analysis
- 9.9TH9.9 Building the Endpoint Threat Hunt Report
- 9.10TH9.10 Converting to Detection Rules
- 9.11TH9.11 Common Mistakes
- 9.12TH9.12 Endpoint Threat Hunt Operational Playbook
- 9.13Module Summary
- 9.14Check My Knowledge
The seventh campaign module. Seven lateral movement techniques hunted across SigninLogs, DeviceNetworkEvents, DeviceLogonEvents, and hybrid identity tables: cloud-to-cloud token reuse across applications, cloud-to-endpoint pivot correlation, RDP/SMB/WMI/PowerShell Remoting detection, service account lateral abuse, VPN pivoting from cloud compromise, NTLM and Kerberos anomalies, and Azure AD Connect abuse.
Show 14 lessonsHide lessons
- 10.1TH10.1 The Lateral Movement Landscape
- 10.2TH10.2 Hunting Cloud Token Reuse Across Applications
- 10.3TH10.3 Hunting Cloud-to-Endpoint Pivot
- 10.4TH10.4 Hunting RDP, SMB, WMI, and PowerShell Remoting
- 10.5TH10.5 Hunting Service Account Lateral Abuse
- 10.6TH10.6 Hunting VPN Pivot. Population Analysis
- 10.7TH10.7 Hunting Credential Harvesting. NTLM and Kerberos Anomalies
- 10.8TH10.8 Hunting Azure AD Connect Abuse
- 10.9TH10.9 Building the Lateral Movement Hunt Report
- 10.10TH10.10 Converting to Detection Rules
- 10.11TH10.11 Common Mistakes
- 10.12TH10.12 Lateral Movement Hunt Operational Playbook
- 10.13Module Summary
- 10.14Check My Knowledge
The eighth campaign module. Seven application and API threat techniques: shadow IT discovery via Cloud App Events, OAuth application inventory and risk scoring, Graph API abuse detection, third-party app excessive permissions, dormant high-privilege applications, AI tool usage with corporate data, and data uploads to unsanctioned services.
Show 14 lessonsHide lessons
- 11.1TH11.1 The Application Threat Landscape
- 11.2TH11.2 Shadow IT Discovery
- 11.3TH11.3 OAuth Application Risk Scoring
- 11.4TH11.4 Hunting Graph API Abuse
- 11.5TH11.5 Hunting Excessive Application Permissions
- 11.6TH11.6 Hunting Dormant Application Reactivation
- 11.7TH11.7 Hunting AI Tool Usage
- 11.8TH11.8 Hunting Unsanctioned File Uploads
- 11.9TH11.9 Building the Application Abuse Hunt Report
- 11.10TH11.10 Converting to Detection Rules
- 11.11TH11.11 Common Mistakes
- 11.12TH11.12 Application Abuse Hunt Operational Playbook
- 11.13Module Summary
- 11.14Check My Knowledge
The ninth campaign module. Six pre-ransomware indicators hunted across DeviceProcessEvents, DeviceFileEvents, DeviceRegistryEvents, and DeviceNetworkEvents: reconnaissance tool execution sequences, volume shadow copy and backup disruption, credential harvesting indicators, staging directory creation, known ransomware tooling signatures, and temporal chain correlation across the full pre-encryption kill chain.
Show 13 lessonsHide lessons
- 12.1TH12.1 The Pre-Ransomware Landscape
- 12.2TH12.2 Hunting Ransomware-Specific Reconnaissance
- 12.3TH12.3 Hunting Backup Disruption
- 12.4TH12.4 Hunting Credential Harvesting for Domain-Wide Deployment
- 12.5TH12.5 Hunting Ransomware Staging
- 12.6TH12.6 Hunting Known Ransomware Tooling
- 12.7TH12.7 Temporal Chain Correlation. The Complete Pre-Ransomware Timeline
- 12.8TH12.8 The Pre-Ransomware Hunt Report
- 12.9TH12.9 Converting Pre-Ransomware Findings to Detection Rules
- 12.10TH12.10 Common Pre-Ransomware Hunting Mistakes
- 12.11TH12.11 Pre-Ransomware Hunt Playbook
- 12.12Module Summary
- 12.13Check My Knowledge
The tenth and final campaign module. Insider threats are entirely different from external attacks, the adversary has legitimate access, their individual actions are authorized, and the detection surface is behavioral deviation rather than signature or anomaly.
Show 14 lessonsHide lessons
- 13.1TH13.1 The Insider Threat Landscape
- 13.2TH13.2 Hunting Data Hoarding and Bulk Access
- 13.3TH13.3 Hunting Access Pattern Deviation
- 13.4TH13.4 Resignation and Termination Correlation
- 13.5TH13.5 Hunting Privilege Abuse by Authorized Users
- 13.6TH13.6 Hunting After-Hours Bulk Activity
- 13.7TH13.7 Hunting External Account Communication
- 13.8TH13.8 Multi-Source Behavioral Assessment
- 13.9TH13.9 The Insider Threat Hunt Report
- 13.10TH13.10 Converting Findings to Detection Rules
- 13.11TH13.11 Common Insider Threat Hunting Mistakes
- 13.12TH13.12 Insider Threat Hunt Playbook
- 13.13Module Summary
- 13.14Check My Knowledge
Phase 3: Hunt Operations
Phase 3 begins. TH0–TH13 taught you how to hunt. TH14–TH16 teach you how to build, sustain, and scale a hunt program. This module covers cadence selection, prioritization frameworks, staffing models, the hunt-to-detection pipeline, SOC integration, and the hunt program charter, the document that formalizes the program and secures leadership support.
Show 10 lessonsHide lessons
- 14.1TH14.1 Hunt Cadence Models
- 14.2TH14.2 Hunt Prioritization Framework
- 14.3TH14.3 Staffing Models
- 14.4TH14.4 The Hunt-to-Detection Pipeline
- 14.5TH14.5 SOC Integration and Budget Justification
- 14.6TH14.6 The Hunt Program Charter
- 14.7TH14.7 Hunt Tooling and Workspace Organization
- 14.8TH14.8 Program Maturity Roadmap
- 14.9Module Summary
- 14.10Check My Knowledge
The hunt program generates findings, negative results, and detection improvements every cycle. Without documentation, these outputs exist in one analyst's memory, lost when they leave, forgotten between quarters, and invisible to leadership.
Show 10 lessonsHide lessons
- 15.1TH15.1 The Hunt Finding Documentation Standard
- 15.2TH15.2 The Value of Negative Findings
- 15.3TH15.3 Reporting to Leadership in Business Language
- 15.4TH15.4 The Technical Hunt Report
- 15.5TH15.5 Building and Maintaining the Hunt Knowledge Base
- 15.6TH15.6 Program Metrics and Dashboards
- 15.7TH15.7 Report Quality Assurance and Stakeholder Communication
- 15.8TH15.8 Finding Trend Analysis and Year-Over-Year Reporting
- 15.9Module Summary
- 15.10Check My Knowledge
The final module. The program is established (TH14), documented (TH15), and producing results.
Show 10 lessonsHide lessons
- 16.1TH16.1 Scheduled Hunting Queries
- 16.2TH16.2 Sentinel Hunt Management
- 16.3TH16.3 Jupyter Notebooks with MSTICPy
- 16.4TH16.4 Hunting Workbooks and Continuous Dashboards
- 16.5TH16.5 The Maturity Continuum
- 16.6TH16.6 Continuous Hunting Operations
- 16.7TH16.7 Course Conclusion
- 16.8TH16.8 Automating Hunt Response with Sentinel Automation
- 16.9Module Summary
- 16.10Check My Knowledge
Phase 0: Course Resources
Hunt queries by domain, each with the fields that carry the decision and what the result does not establish.
Six runbooks: executing a hunt, converting findings to detections, working an advisory, sprints, the backlog, and reporting.
Building an environment you can hunt in, and the constraint that separates a hunting lab from every other kind.
Show 1 lessonHide lessons
Worked hunts end to end, including the wrong turns, the null results, and the candidate that looked certain and was not.
One operational playbook per hunt domain: the sequence, what to record at each step, and what escalates.
Show 10 lessonsHide lessons
Resources for practicing hunting and using it at work: a corpus with history, guided investigations, the detection library, response procedures, and a DFIR toolkit.
The consolidated lookup and the step-by-step procedures from this course, in one place.
Show 2 lessonsHide lessons
External sources this course draws on: vendor documentation, frameworks, standards, and research.
Course Completion
Microsoft Threat Hunting end-of-course exam: a three-phase simulation testing whether you can apply the method to a situation the course did not walk through.
Show 1 lessonHide lessons
Course overview
The Microsoft Threat Hunting course is the core training track for hypothesis-driven hunting, designed for Detection Engineers, Security Engineers, and Hunt Team Leads. You'll gain hands-on expertise to:
By the end, you'll have the mindset, techniques, and practical skills to lead proactive threat hunting programs that significantly improve your organization's detection and response capabilities.
How this course works
A hunt is a hypothesis you can be wrong about, run against data with a stated coverage. This course runs the same cycle for every hunt it works, sixteen modules of it.
1. Write a hypothesis that can fail. If no result would change your mind, it is not a hunt. The falsifiable version is what makes an empty outcome reportable.
2. Establish how far back you can look. Retention differs by table and by license tier, and a hypothesis about six months ago is bounded by the shortest source it touches.
3. Query for the behavior, then baseline it. A result is not a finding until it has been compared against what normal looks like in your estate.
4. Check the entity before escalating. An event inside your window is not evidence your hypothesis was right. The entity check is what separates a finding from a coincidence.
5. Convert the finding into a rule, and the miss into coverage. A hunt that found something should end as a detection. A hunt that found nothing should end as a coverage statement naming what was searched.
The course closes on building the hunt program: a backlog with an order, documentation that outlives the hunter, and hunts that run without one.
What this course assumes
No minimum experience and no prerequisite course. KQL, the ATT&CK model and the M365 telemetry surface are introduced where they first matter.
What makes it go faster: a tenant with real telemetry and any prior KQL. Neither is required. Every hunt in the course runs against the Practice Hub, which holds populated tables and known answers.
What this course does not cover: incident response process, forensics and detection engineering as a program. A hunt hands off to those, and the handoff is taught rather than the destination.
Who this course is for
You're a Detection Engineer, Security Engineer, or Hunt Team Lead responsible for proactive, hypothesis-driven threat hunting in Microsoft 365 environments. This course is built for you if you want to:
In short: if you're ready to become a highly effective threat hunter who actively finds attackers before they cause damage, this course is for you.
What you'll learn
By the end of this Microsoft Threat Hunting course you will be able to:
Key course takeaways
Lab Pack, Hypothesis-Driven Hunt Toolkit
Evidence (9 tables, 30-day window, ~4,000+ entries): SigninLogs, AuditLogs, OfficeActivity, DeviceProcessEvents, DeviceNetworkEvents, EmailEvents, DeviceFileEvents, DeviceRegistryEvents, with multiple attack chains hidden in legitimate baseline noise.
Hunt query library (~70 KQL files across 10 domains): Identity, Persistence, Escalation, Email, Exfiltration, Endpoint, Lateral Movement, Application, Ransomware, Insider, and Advanced correlation queries.
10 structured hypotheses with ATT&CK mapping and success criteria. Answers deliberately withheld, you must hunt.
Program artifacts: Charter, sprint template, maturity model, metrics template, hunt report templates, ATT&CK coverage matrix.
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches hypothesis-driven threat hunting from first principles. Familiarity with KQL and the Microsoft security stack will help you move faster, but neither is required. Every concept is explained at first use.
What are the device requirements?
A device with a modern browser. Access to a Microsoft 365 E5 tenant (a developer subscription if you qualify for one, otherwise a 30-day E5 trial) with Sentinel and Defender XDR for hands-on hunting. The lab pack provides synthetic evidence data if you cannot use a live environment.
How will the course benefit your career?
Threat hunting is one of the highest-value skills in security operations. Organizations need people who can proactively find threats that detection rules miss, not just triage alerts. This course gives you the methodology, the KQL fluency, and the hunt program framework to lead hunting operations.
The demand for threat hunters continues to grow as organizations recognize that detection rules alone cannot close the gap between attacker dwell time and discovery.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy hunt queries, detection rules, and playbooks in your production environment. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.