Roadmap, security and documentation changes captured for Advanced Hunting.
PreviewMicrosoft Defender XDRAdvanced Hunting
Local AI agent discovery on Windows endpoints: as part of the Defender AI agents experience, Microsoft Defender now automatically discovers supported local AI agents running on onboarded Windows devices - including coding agents and IDE extensions, desktop AI assistants, local AI runtimes, and agent platforms. Discovered agents appear as assets in the AI agent inventory, exposure map, and advanced hunting, giving security teams visibility into local AI agent usage across the organization. For more information, see Discover local AI agents.
GA×2 recordsMicrosoft Defender XDRDefender for CloudAdvanced Hunting
The following advanced hunting schema tables are now generally available: The DisruptionAndResponseEvents table contains information about automatic attack disruption events in Microsoft Defender XDR. The `CloudAuditEvents` table contains information about cloud audit events for various cloud platforms protected by the organization's Microsoft Defender for Cloud. The `CloudDnsEvents` table contains information about DNS activity events from cloud infrastructure environments. The `CloudProcessEvents` table contains information about process events in multicloud hosted environments.
PreviewMicrosoft Defender XDRAdvanced Hunting
The `AgentsInfo` table in advanced hunting is now available in preview. The `AIAgentsInfo` table is transitioning to this new table, which provides a unified schema that supports agent inventory and governance for all agent types, including Copilot Studio, Microsoft Foundry, Microsoft 365 Copilot, third-party, and endpoint-discovered agents. Microsoft Agent 365 customers should use the `AgentsInfo` table today. The `AIAgentsInfo` table remains accessible until July 1, 2026. Update your queries to use `AgentsInfo` before this date. For more information, see Advanced hunting schema - Naming changes.
defenderMicrosoft Defender XDRAdvanced Hunting
In advanced hunting, the Take action wizard now lets customers allow or block top-level domains and files attachment hashes in emails based on query results. Learn more.
defenderMicrosoft Defender XDRAdvanced Hunting
The hunting graph in advanced hunting now includes new identity-focused predefined scenarios. These scenarios help you discover attack paths, privilege escalation routes, and credential access risks across on-premises and cloud environments, including Kerberoast and AS-REP roast paths, domain compromise routes, OAuth application risks, and guest user access to cloud resources.
PreviewMicrosoft Defender XDRAdvanced Hunting
The `AIAgentsInfo` table in advanced hunting now includes additional columns that provide deeper visibility into AI agents operating in your Microsoft 365 environment. These fields expand coverage beyond Copilot Studio to all agent types, including Microsoft Foundry, third-party marketplace, and custom line-of-business agents.
Preview×3 recordsMicrosoft Defender XDRDefender for CloudAdvanced Hunting
The following advanced hunting schema tables are now available for preview: The `CloudDnsEvents` table contains information about DNS activity events from cloud infrastructure environments. The `CloudPolicyEnforcementEvents` table contains policy enforcement evaluation decisions and metadata of security gating events for various cloud platforms protected by the organization's Microsoft Defender for Cloud.
PreviewMicrosoft Defender XDRAdvanced Hunting
In advanced hunting, if the query result exceeds the 64-MB size limit, the portal now returns the maximum number of records it can within this limit and displays a message indicating that the displayed results are partial due to size constraints. Learn more
PreviewMicrosoft Defender XDRAdvanced Hunting
The `BehaviorInfo` and `BehaviorEntities` tables in advanced hunting now include additional columns and information about behavior data types and alerts from User and Entity Behavior Analytics (UEBA), providing more insights on the relationships between identified behaviors and entities. Learn more about UEBA behaviors
GAMicrosoft Defender XDRAdvanced Hunting
The hunting graph in advanced hunting is now generally available. It also now has two new predefined threat scenarios that you can use to render your hunts as interactive graphs.
GAMicrosoft Defender XDRAdvanced Hunting
Advanced hunting now supports custom functions that use tabular parameters. By using tabular parameters, you can pass entire tables as inputs. This approach lets you build more modular, reusable, and expressive logic across your hunting queries. Learn more
PreviewMicrosoft Defender XDRAdvanced Hunting
The `IdentityAccountInfo` table in advanced hunting is now available for preview. This table contains information about account information from various sources, including Microsoft Entra ID. It also includes information and link to the identity that owns the account.
PreviewMicrosoft Defender XDRAdvanced Hunting
In advanced hunting, you can now hunt by using the hunting graph, which renders predefined threat scenarios as interactive graphs.
PreviewMicrosoft Defender XDRAdvanced Hunting
In advanced hunting, you can now enrich your custom detection rules by creating dynamic alert titles and descriptions, select more impacted entities, and add custom details to display in the alert side panel. Microsoft Sentinel customers that are onboarded to Microsoft Defender also now have the option to customize the alert frequency when the rule is based only on data that is ingested to Sentinel.
PreviewMicrosoft Defender XDRDefender for CloudAdvanced Hunting
Advanced hunting now lets you investigate Microsoft Defender for Cloud behaviors. For more information, see Investigate behaviors with advanced hunting.
PreviewMicrosoft Defender XDRAdvanced Hunting
In advanced hunting, the number of query results displayed in the Microsoft Defender portal has been increased to 100,000.
GA×2 recordsMicrosoft Defender XDRAdvanced Hunting
In advanced hunting, you can now view all your user-defined rules—both custom detection rules and analytics rules—in the Detection rules page. This feature also brings the following improvements: You can now filter for *every* column (in addition to Frequency and Organizational scope). For multiworkspace organizations that onboard multiple workspaces to Microsoft Defender, you can now view the Workspace ID column and filter by workspace. You can now view the details pane even for analytics rules. You can now perform the following actions on analytics rules: Turn on/off, Delete, Edit. (GA) The Sensitivity label filter is now available in the Incidents and Alerts queues in the Microsoft Defender portal. This filter lets you filter incidents and alerts based on the sensitivity label assigned to the affected resources. For more information, see Filters in the incident queue and Investigate alerts.
PreviewMicrosoft Defender XDRAdvanced Hunting
The `GraphApiAuditEvents` table in advanced hunting is now available for preview. This table contains information about Microsoft Entra ID API requests made to Microsoft Graph API for resources in the tenant.
PreviewMicrosoft Defender XDRAdvanced Hunting
The `DisruptionAndResponseEvents` table, now available in advanced hunting, contains information about automatic attack disruption events in Microsoft Defender XDR. These events include both block and policy application events related to triggered attack disruption policies, and automatic actions that were taken across related workloads. Increase your visibility and awareness of active, complex attacks disrupted by attack disruption to understand the attacks' scope, context, impact, and actions taken.
GAMicrosoft Defender XDRAdvanced Hunting
In advanced hunting, Microsoft Defender portal users can now use the `adx()` operator to query tables stored in Azure Data Explorer. You no longer need to go to log analytics in Microsoft Sentinel to use this operator if you're already in Microsoft Defender.
defenderMicrosoft Defender XDRAdvanced Hunting
Defender portal users who onboard Microsoft Sentinel and enable the User and Entity Behavior Analytics (UEBA) can now take advantage of the new unified `IdentityInfo` table in advanced hunting. This latest version now includes the largest possible set of fields common to both Defender and Azure portals.
PreviewMicrosoft Defender XDRAdvanced Hunting
The following advanced hunting schema tables are now available for preview to help you look through Microsoft Teams events and related information: The MessageEvents table contains details about messages sent and received within your organization at the time of delivery The MessagePostDeliveryEvents table contains information about security events that occurred after the delivery of a Microsoft Teams message in your organization The MessageUrlInfo table contains information about URLs sent through Microsoft Teams messages in your organization