Agent Threat Hunting & Investigation
Correlates AI agent alerts into incidents and gives analysts an incident graph to scope the blast radius, then queries Agent 365 observability data with Kusto Query Language in Advanced Hunting — across the AgentsInfo, CloudAppEvents, and BehaviorInfo tables — to investigate threats and proactively hunt for risk. Turns near-real-time agent detections into full investigation and threat-hunting workflows in the Microsoft Defender portal.