Gundog : Guided Hunting In Microsoft 365 Defender

From kalilinuxtutorials.com

Gundog : Guided Hunting In Microsoft 365 Defender

gundog – PowerShell based guided hunting in Microsoft 365 Defender

Gundog provides you with guided hunting in Microsoft 365 Defender. Especially (if not only) for Email and Endpoint Alerts at the moment.

You provide an AlertID (you might received via Email notification) and gundog will then hunt for as much as possible associated data. It does not give you the flexibility of advanced hunting like you have in the portal, but it will give you a quick, first overview of the alert, all associated entities and some enrichment.

Read more…