{ "opencollection": "1.0.0", "info": { "name": "Microsoft Graph Admin Admin.admin security.security.Actions API", "version": "1.0.0" }, "items": [ { "info": { "name": "security.security.Actions", "type": "folder" }, "items": [ { "info": { "name": "Microsoft Graph Invoke action runHuntingQuery", "type": "http" }, "http": { "method": "POST", "url": "https://graph.microsoft.com/v1.0/security/microsoft.graph.security.runHuntingQuery", "body": { "type": "json", "data": "{}" } }, "docs": "Queries a specified set of event, activity, or entity data supported by Microsoft 365 Defender to proactively look for specific threats in your environment. This method is for advanced hunting in Microsoft 365 Defender. This method includes a query in Kusto Query Language (KQL). It specifies a data table in the advanced hunting schema and a piped sequence of operators to filter or search that data, and format the query output in specific ways. Find out more about hunting for threats across devi" } ] } ], "bundled": true }