services / Azure / Microsoft Sentinel hunt
A Microsoft Sentinel hunt, a proactive threat-hunting investigation record capturing hypotheses, queries, findings, and linked evidence.
Hunts hold proactive investigation context rather than live detection logic; deleting them destroys investigation records but does not disable the platform, so this is MEDIUM.
Microsoft.SecurityInsights/hunts/write
Updating a hunt lets an attacker alter findings or hypotheses to steer a hunt away from their activity and mislead threat hunters.
Risks
Scope: MEDIUM
This privilege may grant access to confidential data, or its exploit can incur operational cost.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog