Skip to content
Notifications
Clear all

Hot take: For the price, the hunting and query tools should be better.

1 Posts
1 Users
0 Reactions
1 Views
 amyt
(@amyt)
Estimable Member
Joined: 1 week ago
Posts: 77
Topic starter   [#17693]

Okay, I’ll be the one to say it. We pay a premium for Microsoft Defender for Endpoint, especially at scale, but when I compare the Advanced Hunting query experience to some other platforms (even some lower-cost ones!), it feels like it hasn't kept pace. The power is there, but the usability? Not so much.

Don't get me wrong—I love the idea. A unified query language across endpoints, emails, and identity logs is fantastic for us data nerds. But the actual workflow in the portal can be clunky. For example:

* Saving and organizing complex queries is a pain. I end up with a massive list of "Untitled query 1, 2, 3..."
* The schema reference feels disconnected. I'm constantly tabbing out to docs instead of having quick, contextual hints in the editor itself.
* Building visualizations from query results is way more manual than it should be. For a tool at this price point, I'd expect a smoother path from query to chart to dashboard.

Maybe I'm spoiled by my sales analytics tools (looking at you, Tableau!), but for hunting threats, speed and clarity are everything. If I'm investigating an incident, I don't want friction in my query tool.

Am I the only one feeling this? How are you all building and sharing your hunting queries? Have you found any good workarounds for managing your library of KQL?

—Amy



   
Quote