Overview

This step-by-step walkthrough is an example of how to configure custom Advanced Hunting in Microsoft Defender ATP using 3 simple steps:
- Create a reusable query
- Create a custom detection rule
- Add a notification rule
1. Create a reusable query
- http://securitycenter.microsoft.com/
- Advanced hunting
- QueryNew
- Type the following query
DeviceProcessEvents
| where ProcessCommandLine contains "notepad.exe"
- Run query
- Review the results to verify “notepad.exe” was found
- SaveSave asDetect_Notepad.exe

2. Create a custom detection rule
- Create detection rule
- Complete the Alert details form (example shown below)

A note about Frequency

4. Carefully review and select the desired device and/or file actions

5. Review the the Summary and click Save

3. Add a notification rule
- Settings
- Under General, select Alert notifications
- Add notification rule
- Complete the New notification rule form (example shown below)

5. Enter valid e-mail recipients and select Send test email

Sample Alert Email
