Lesson 15 — Microsoft Sentinel Bookmarks
Microsoft Sentinel Bookmarks allows analysts to search security data proactively instead of waiting for an alert or incident to be created.
A hunt begins with a question or hypothesis, uses KQL to test that idea and follows the evidence across users, devices, IP addresses, applications and timelines.
Strong hunting turns unknown activity into understood evidence and can lead to bookmarks, investigations, incidents and new analytics rules.
What you will learn
This lesson explains how analysts use Microsoft Sentinel Bookmarks to search proactively for suspicious activity.
Learning objectives
After completing this lesson, you should understand how Microsoft Sentinel Bookmarks help analysts preserve investigation evidence and context.
- Explain what a Microsoft Sentinel Bookmark is.
- Understand when analysts create Bookmarks.
- Recognise the value of notes, tags and entity mappings.
- Understand how Bookmarks support hunting and investigations.
- Apply practical documentation and evidence-handling practices.
The problem this solves
Analysts often find suspicious events before they know whether a full incident exists.
Bookmarks preserve those findings so evidence is not lost while the investigation continues.
What is a Microsoft Sentinel Bookmark?
A Bookmark is a saved investigation artefact created from an interesting query result or event. It preserves the evidence, the analyst's notes and the context required to understand why the result mattered.
A useful Bookmark should explain why the event matters, not simply copy the event itself.
How Bookmarks fit into an investigation
Where Bookmarks are created
Analysts commonly create Bookmarks from Hunting results, Logs queries and other investigation views where a specific event needs to be preserved.
What a Bookmark can contain
- The original query result
- Event timestamp
- Analyst notes
- Tags
- Mapped entities
- Investigation details
Analyst notes
Notes should clearly explain what was observed, why it appears suspicious and what the next analyst should investigate.
A Bookmark without useful notes may preserve evidence but lose its meaning.
Tags
Tags help analysts group and find related Bookmarks.
Examples include phishing, malware, lateral movement, privileged access, false positive and investigation pending.
Entity mappings
Mapped entities connect the Bookmark to accounts, hosts, IP addresses, URLs, files and other security objects.
This makes it easier to pivot from saved evidence into broader Sentinel investigations.
Bookmarks and Hunting
Hunting is exploratory. Bookmarks provide a structured way to save the results that deserve further attention.
They allow analysts to build an evidence trail while a hypothesis develops.
Bookmark versus incident
| Bookmark | Incident |
|---|---|
| Preserves a finding or piece of evidence. | Represents a security case requiring investigation and response. |
| Often created manually by an analyst. | Often created automatically by analytics rules. |
| Supports hunting, notes and evidence collection. | Supports ownership, severity, status and response workflow. |
| May exist before a threat is confirmed. | Usually represents correlated alerts or a confirmed investigation path. |
What good notes include
- Why the event is relevant
- The user, device or IP involved
- Related indicators
- Observed timeline
- Next investigation steps
Common SOC use cases
- Saving suspicious sign-ins
- Preserving unusual PowerShell activity
- Recording malicious URL evidence
- Tracking lateral movement indicators
- Building a timeline before escalation
Collaboration
Bookmarks allow another analyst to understand what was found and why it mattered.
Clear documentation reduces duplicated work and helps investigations continue across shifts.
Common mistake
A common mistake is creating a Bookmark with no meaningful description.
Months later, the evidence remains but nobody remembers why it was saved.
Agent Foskett investigation tip
Write every Bookmark so someone else can continue the investigation without needing to ask what you meant.
Best practices
- Use consistent tags.
- Write clear and specific notes.
- Map the relevant entities.
- Link evidence to the investigation timeline.
- Review and clean up obsolete Bookmarks.
Agent Foskett takeaway
Bookmarks turn interesting query results into durable investigation evidence.
Good Bookmarks preserve the event, explain its importance and help analysts work together.
Related Agent Foskett learning
Continue learning
Microsoft Sentinel Bookmarks
Microsoft Sentinel Bookmarks allow SOC analysts to preserve investigation evidence, notes, tags, entities and context from hunting and log query results.
Microsoft Sentinel Lesson 15
This Agent Foskett Microsoft Sentinel Academy lesson explains how Bookmarks support threat hunting, collaboration, evidence preservation, investigation timelines and SOC documentation.
