Agent Foskett Academy • Microsoft Sentinel • Module 2 • Lesson 15

Lesson 15 — Microsoft Sentinel Bookmarks

Microsoft Sentinel Bookmarks allows analysts to search security data proactively instead of waiting for an alert or incident to be created.

A hunt begins with a question or hypothesis, uses KQL to test that idea and follows the evidence across users, devices, IP addresses, applications and timelines.

Strong hunting turns unknown activity into understood evidence and can lead to bookmarks, investigations, incidents and new analytics rules.

Great hunters do not wait for alerts. They ask questions of the data and follow the evidence.
Agent Foskett Microsoft Sentinel Bookmarks lesson
What you will learn

This lesson explains how analysts use Microsoft Sentinel Bookmarks to search proactively for suspicious activity.

What bookmark-based investigations is
How hypotheses guide hunts
How KQL and bookmarks are used
When to create a detection rule

Learning objectives

After completing this lesson, you should understand how Microsoft Sentinel Bookmarks help analysts preserve investigation evidence and context.

  • Explain what a Microsoft Sentinel Bookmark is.
  • Understand when analysts create Bookmarks.
  • Recognise the value of notes, tags and entity mappings.
  • Understand how Bookmarks support hunting and investigations.
  • Apply practical documentation and evidence-handling practices.

The problem this solves

Analysts often find suspicious events before they know whether a full incident exists.

Bookmarks preserve those findings so evidence is not lost while the investigation continues.

What is a Microsoft Sentinel Bookmark?

A Bookmark is a saved investigation artefact created from an interesting query result or event. It preserves the evidence, the analyst's notes and the context required to understand why the result mattered.

Agent Foskett tip:

A useful Bookmark should explain why the event matters, not simply copy the event itself.

How Bookmarks fit into an investigation

Run hunting or log query │ ▼ Identify interesting result │ ▼ Create Bookmark │ ├── Preserve event details ├── Add analyst notes ├── Apply tags ├── Map relevant entities └── Record investigation context │ ▼ Continue, share or escalate the investigation

Where Bookmarks are created

Analysts commonly create Bookmarks from Hunting results, Logs queries and other investigation views where a specific event needs to be preserved.

What a Bookmark can contain

  • The original query result
  • Event timestamp
  • Analyst notes
  • Tags
  • Mapped entities
  • Investigation details

Analyst notes

Notes should clearly explain what was observed, why it appears suspicious and what the next analyst should investigate.

A Bookmark without useful notes may preserve evidence but lose its meaning.

Tags

Tags help analysts group and find related Bookmarks.

Examples include phishing, malware, lateral movement, privileged access, false positive and investigation pending.

Entity mappings

Mapped entities connect the Bookmark to accounts, hosts, IP addresses, URLs, files and other security objects.

This makes it easier to pivot from saved evidence into broader Sentinel investigations.

Bookmarks and Hunting

Hunting is exploratory. Bookmarks provide a structured way to save the results that deserve further attention.

They allow analysts to build an evidence trail while a hypothesis develops.

Bookmark versus incident

BookmarkIncident
Preserves a finding or piece of evidence.Represents a security case requiring investigation and response.
Often created manually by an analyst.Often created automatically by analytics rules.
Supports hunting, notes and evidence collection.Supports ownership, severity, status and response workflow.
May exist before a threat is confirmed.Usually represents correlated alerts or a confirmed investigation path.

What good notes include

  • Why the event is relevant
  • The user, device or IP involved
  • Related indicators
  • Observed timeline
  • Next investigation steps

Common SOC use cases

  • Saving suspicious sign-ins
  • Preserving unusual PowerShell activity
  • Recording malicious URL evidence
  • Tracking lateral movement indicators
  • Building a timeline before escalation

Collaboration

Bookmarks allow another analyst to understand what was found and why it mattered.

Clear documentation reduces duplicated work and helps investigations continue across shifts.

Common mistake

A common mistake is creating a Bookmark with no meaningful description.

Months later, the evidence remains but nobody remembers why it was saved.

Agent Foskett investigation tip

Your future self is another analyst.

Write every Bookmark so someone else can continue the investigation without needing to ask what you meant.

Best practices

  • Use consistent tags.
  • Write clear and specific notes.
  • Map the relevant entities.
  • Link evidence to the investigation timeline.
  • Review and clean up obsolete Bookmarks.

Agent Foskett takeaway

Bookmarks turn interesting query results into durable investigation evidence.

Good Bookmarks preserve the event, explain its importance and help analysts work together.

Lesson summary
Microsoft Sentinel Bookmarks preserve interesting events, analyst notes, tags, entities and investigation context. They help hunters build evidence trails, collaborate across shifts and avoid losing important findings.
Sentinel Academy Home

Microsoft Sentinel Bookmarks

Microsoft Sentinel Bookmarks allow SOC analysts to preserve investigation evidence, notes, tags, entities and context from hunting and log query results.

Microsoft Sentinel Lesson 15

This Agent Foskett Microsoft Sentinel Academy lesson explains how Bookmarks support threat hunting, collaboration, evidence preservation, investigation timelines and SOC documentation.