services / Azure / Microsoft Sentinel hunt
A Microsoft Sentinel hunt, a proactive threat-hunting investigation record capturing hypotheses, queries, findings, and linked evidence.
Hunts hold proactive investigation context rather than live detection logic; deleting them destroys investigation records but does not disable the platform, so this is MEDIUM.
Microsoft.SecurityInsights/hunts/delete
Deleting a hunt destroys the proactive-investigation record and its linked findings, erasing the trail of what was examined.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog