Microsoft Defender XDR Custom Detection Rules: A Complete Guide & Best Practices
ID: fd6e4d26-712a-52e8-8287-d7e2e0239d1a
STIX ID: report--fd6e4d26-712a-52e8-8287-d7e2e0239d1a
Feed Name: Detect FYI
This consolidated guide explains how to build and tune Microsoft Defender XDR custom detection rules, covering required identifier columns, frequency and near‑real‑time (NRT) constraints, enrichment and entity mapping, automatic response actions, the SentinelScope_CF scoping change, limits (150-alert cap, 4 KB custom details, 30-day initial scan), and recommended testing and migration best practices to avoid floods of historical alerts and missing enrichments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
