Microsoft Defender XDR Hunting Schema Investigation
Use Microsoft Defender XDR's official advanced-hunting schema to select event tables, interpret process and network fiel...
8 questions · 45 minUse SigmaHQ's official rules, log sources, and conditions documentation. Research rule semantics before answering; do not assume a Sigma rule is already a query for a specific SIEM.
Sign in to answer the questions, save your result and receive a certificate when you pass.