AI-Native SIEM Platforms
Modern SIEM platforms — including Microsoft Sentinel — provide the data foundation for AI-powered hunting, combining large-scale log aggregation with machine learning-based anomaly detection and natural language querying capability through tools like Copilot for Security.
Sentinel’s KQL query language, combined with Copilot’s natural language interface, enables hunters to investigate hypotheses across the full breadth of ingested telemetry — with AI assistance translating analytical questions into executable queries and summarizing results in plain language.
XDR Platforms
Extended Detection and Response (XDR) platforms provide cross-domain telemetry correlation that makes threat hunting significantly more effective — connecting endpoint, identity, email, cloud, and network signals into a unified data set that hunters can investigate across domain boundaries rather than in siloed tools.
Microsoft Defender XDR extends hunting capability through its advanced hunting interface — enabling hunters to query normalized telemetry from across the Defender product family using a unified schema.
Behavioral Analytics Platforms
User and Entity Behavior Analytics (UEBA) platforms provide behavioral baselines and anomaly scores for users and entities across the environment — giving hunters a prioritized set of behavioral anomalies to investigate rather than requiring them to identify starting points manually from raw telemetry.
AI Hunting Agents
Emerging AI hunting agents — specialized components within multi-agent SOC architectures — conduct autonomous hunting, generating and investigating hypotheses continuously and surfacing findings for human review. These agents represent the leading edge of hunting automation, extending proactive coverage beyond what any human-driven hunting program can achieve through staffing alone.
Learn more: What Is an AI SOC Agent?