Skip to content

Dashboards Design

Microsoft Sentinel dashboards are critical for visualizing threat hunting results, tracking indicators, and enabling rapid analysis. Effective dashboards balance clarity, interactivity, and contextual depth to help analysts identify patterns, anomalies, and potential threats. This section outlines principles for designing dashboards that align with threat hunting workflows.

Prioritize Relevance and Context

Focus on indicators and events most relevant to your hunting goals. Use filters, drill-down capabilities, and contextual metadata (e.g., user, host, or process details) to avoid information overload. For example, a dashboard tracking lateral movement might highlight process creation events with suspicious parent-child relationships.

Example: A KQL query to filter process creation events for potential lateral movement:

ProcessCreationEvent
| where ProcessName contains "cmd.exe" and ParentProcessName != "explorer.exe"
| project TimeGenerated, Computer, ProcessName, ParentProcessName, ParentProcessPath
Use this query as a basis for a dashboard tile that highlights suspicious process chains.

Leverage Time-Based Analysis

Time is a critical dimension in threat hunting. Use time-based visualizations (e.g., timelines, heatmaps, or trend charts) to identify anomalies in activity patterns. For example, a spike in process creation events during off-hours might indicate a compromise.

Example: A timeline visualization to track suspicious activity over time:

ProcessCreationEvent
| where ProcessName contains "powershell.exe" and TimeGenerated > ago(7d)
| summarize count() by bin(TimeGenerated, 1h)
| render timechart
This query aggregates process creation events hourly, enabling trend analysis.

Incorporate Threat Intelligence

Integrate threat intelligence (TI) feeds to enrich dashboards with known malicious indicators (e.g., IPs, domains, or hashes). Use joins or lookups to correlate Sentinel logs with TI data. For example, a dashboard might highlight events involving known malicious domains.

Example: A query to join process creation events with a TI list of malicious domains:

ProcessCreationEvent
| where ProcessName contains "cmd.exe"
| join (threatintel_malicious_domains) on ProcessCommandLine
| project TimeGenerated, Computer, ProcessName, ProcessCommandLine, Domain
This helps analysts quickly identify commands involving known malicious domains.

Enable Interactive Exploration

Design dashboards with interactive elements (e.g., dropdowns, sliders, or filters) to allow analysts to adjust parameters dynamically. For instance, a dropdown to select a specific IP address or time range can refine results in real time.

Example: A parameterized query for IP-based investigation:

ProcessCreationEvent
| where Computer == param("TargetComputer", "192.168.1.100")
| project TimeGenerated, ProcessName, ParentProcessName, ParentProcessPath
This query can be embedded in a dashboard with a dropdown to select the target computer.

Automate Alerting and Escalation

Use Microsoft Sentinel's alerting capabilities to automate notifications for critical findings. Define rules that trigger alerts based on thresholds (e.g., a high volume of suspicious process creations).

Example: A rule to alert on excessive process creation events:

ProcessCreationEvent
| where ProcessName contains "cmd.exe" and ParentProcessName != "explorer.exe"
| summarize count() by Computer
| where count_ > 50
| project Computer, count_
This rule triggers an alert if a single host exceeds 50 suspicious process creations, enabling rapid escalation.

Key takeaways

  • Focus on relevance: Filter dashboards to highlight indicators aligned with your hunting objectives.
  • Use time context: Leverage time-based visualizations to detect anomalies in activity patterns.
  • Integrate TI: Enrich dashboards with threat intelligence to identify known malicious indicators.
  • Enable interactivity: Allow analysts to dynamically adjust filters and parameters for deeper exploration.
  • Automate alerts: Use rules to flag critical findings and streamline incident response workflows.