Memory hook: A query finds evidence; a detection makes it actionable.
Must remember
Start with a threat hypothesis and required telemetry. Scheduled Sentinel analytics rules run a query on a configured cadence/lookback; near-real-time rules have their own supported constraints. Thresholds, entity mapping, grouping and suppression decide how query results become alerts and incidents. A rule that runs successfully can still miss events arriving outside its effective window.
Defender custom detections use supported advanced-hunting tables and required identifying fields. Preserve the identifiers and timestamps needed to create useful alerts or response actions. Map detections to MITRE ATT&CK techniques to expose coverage gaps; a colored matrix is not evidence that each technique is reliably detected.
Tune with labeled examples. Narrow exclusions to known expected behavior, measure false positives and keep a way to detect abuse of the exception. Threat-intelligence matches and anomaly/ML signals need context and validation. Suppressing a noisy alert globally can hide a real attack using the same pattern.
Sentinel automation rules react to supported incident/alert conditions and can update fields, assign work or invoke playbooks. Playbooks run Logic Apps workflows and need authorized identities for their connectors/actions. Distinguish a rule's trigger from the playbook's trigger and test error/retry paths. A repeated event should not repeatedly disable a legitimate account without control.
Automated investigation and response and automatic attack disruption can contain activity across supported Defender signals. Configure prerequisites, scope and approval/automation levels deliberately. Keep evidence, record actions and verify recovery. Automation speed is useful only when the detection, permissions and rollback are trustworthy.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Recurring query becomes an incident | Analytics rule with entities, thresholds and grouping. |
| Route and enrich a new incident | Automation rule and an appropriately triggered playbook. |
| Evaluate detection coverage | Map validated detections to ATT&CK and inspect telemetry gaps. |
Traps
- Rule success is not proof of detection effectiveness.
- A broad suppression can remove evidence of real abuse.
Active recall
1. Why overlap a lookback appropriately?
To tolerate ingestion delay while controlling duplicate alerts.
2. Why map entities?
To connect evidence to accounts, hosts, addresses and investigation context.
3. Automation rule versus playbook?
Incident/alert handling logic versus the workflow that performs integrated actions.
4. Why make response idempotent?
Retries and repeated events should not cause uncontrolled duplicate effects.
5. What validates an ATT&CK coverage claim?
Representative evidence and successful detection tests, not merely a tag.