Skip to content

Latest commit

 

History

History
51 lines (39 loc) · 2.18 KB

File metadata and controls

51 lines (39 loc) · 2.18 KB
title Overview of custom detections in Microsoft Defender XDR
description Understand how you can use advanced hunting to create custom detections and generate alerts.
search.appverid met150
ms.service defender-xdr
ms.subservice adv-hunting
f1.keywords
NOCSH
ms.author pauloliveria
author poliveria
ms.localizationpriority medium
manager dansimp
audience ITPro
ms.collection
m365-security
tier2
ms.custom
cx-ti
cx-ah
ms.topic overview
appliesto
Microsoft Defender XDR
Microsoft Sentinel in the Microsoft Defender portal
ms.date 06/27/2024

Custom detections overview

[!INCLUDE Microsoft Defender XDR rebranding]

With custom detections, you can proactively monitor for and respond to various events and system states, including suspected breach activity and misconfigured endpoints. Custom detections are customizable detection rules that automatically trigger alerts and response actions.

Custom detections work with advanced hunting, which provides a powerful, flexible query language that covers a broad set of event and system information from your network. You can set them to run at regular intervals, generating alerts and taking response actions whenever there are matches.

Custom detections provide:

  • Alerts for rule-based detections built from advanced hunting queries
  • Automatic response actions

Optimizing your queries in custom detection rules is important in avoiding time-outs and ensuring efficiency. There are several resources available that provide guidance on optimizing your queries in Advanced hunting query best practices.

See also

[!INCLUDE Microsoft Defender XDR rebranding]