Microsoft Sentinel: hunting, watchlists, threat intelligence, UEBA and rule health
For SOC analysts and engineers who already run analytics rules and incidents in Microsoft Sentinel. Learn the parts Microsoft documents for proactive work and for keeping detections healthy: hunting queries, hunts and bookmarks, watchlists as reference data, threat intelligence tables and matching analytics, UEBA tables and scores, and the troubleshooting articles on rules that are AUTO DISABLED, rules that stop working across tenants, and alerts missed because of ingestion delay. Concepts and vocabulary come from Microsoft Learn; portals change, so confirm in current documentation.
- Level
- Advanced
- Length
- About 55 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 2 Oct 2026
- Microsoft Sentinel
Skills you'll practise
- Use the Hunting page's results, deltas and MITRE mapping to choose where to hunt, and preserve evidence with bookmarks
- Design a watchlist within Microsoft's limits and query it efficiently with _GetWatchlist and its SearchKey
- Explain where threat indicators are stored and what the Microsoft Defender Threat Intelligence Analytics rule matches
- Interpret UEBA tables and the InvestigationPriority and AnomalyScore values
- Diagnose AUTO DISABLED and cross-tenant rule failures and adjust a scheduled rule for ingestion delay without creating duplicates
Course outline
- 1.Sentinel: hunting, watchlists, threat intelligence, UEBA and rule healthVideo · 2 min
- 2.Hunting, hunts and bookmarksLesson · 17 min
- 3.Watchlists and threat intelligenceLesson · 18 min
- 4.UEBA and keeping detections healthyLesson · 18 min
- 5.Microsoft Sentinel: hunting, watchlists, threat intelligence, UEBA and rule health: knowledge checkKnowledge check · 17 questions
- 6.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Microsoft Learn: Threat hunting in Microsoft Sentinel
- Microsoft Learn: Conduct end-to-end proactive threat hunting in Microsoft Sentinel
- Microsoft Learn: Keep track of data during hunting with Microsoft Sentinel (bookmarks)
- Microsoft Learn: Watchlists in Microsoft Sentinel
- Microsoft Learn: Build queries or detection rules with watchlists in Microsoft Sentinel
- Microsoft Learn: Threat intelligence in Microsoft Sentinel
- Microsoft Learn: Use matching analytics to detect threats
- Microsoft Learn: Identify threats using User and Entity Behavior Analytics (UEBA)
- Microsoft Learn: Enable User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel
- Microsoft Learn: Troubleshooting analytics rules in Microsoft Sentinel
- Microsoft Learn: Handle ingestion delay in scheduled analytics rules
- Microsoft Learn: Monitor the health and audit the integrity of your analytics rules
- Microsoft Learn: Auditing and health monitoring in Microsoft Sentinel
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.