Lesson 42 — Using Bookmarks During an Investigation
You run a query and find one event that changes the case.
Then you run another query.
Then another.
Two hours later, can you still find that first event?
That is why investigators preserve evidence.

What you will learn
Preserve the findings that matter without turning the case into a scrapbook.
Learning objectives
- Explain the operational purpose of a Microsoft Sentinel hunting bookmark.
- Recognise investigation findings that are worth preserving.
- Add useful notes, tags and entity context to a bookmark.
- Use bookmarks to enrich an existing incident and its timeline.
- Return from a bookmark to its source query and preserved result.
- Avoid over-bookmarking low-value or unexplained data.
This is not Lesson 15 again
Lesson 15 introduced Microsoft Sentinel bookmarks as a hunting capability.
Now we are inside a live investigation.
The question is no longer “What is a bookmark?”
It is “Which evidence is important enough to preserve?”
What does a bookmark preserve?
Microsoft Sentinel hunting bookmarks preserve query results that an analyst considers relevant. They can also retain contextual observations through notes and tags, helping analysts and teammates return to important findings later.
A bookmark is not an alert
An alert is normally generated because detection logic matched defined conditions.
A bookmark is an analyst-preserved finding. It records something the investigator decided was worth keeping.
A bookmark is not a conclusion
Saving a result does not make it malicious.
A bookmark may represent suspicious activity, a possible root cause, an indicator, a useful pivot or simply evidence that needs further investigation.
The Agent Foskett bookmark test
Good bookmark candidates
- A suspicious event that predates the first alert.
- A possible initial-access event.
- A newly discovered indicator of compromise.
- A persistence or privilege change.
- An event connecting two previously separate entities.
- A result that materially changes incident scope.
Poor bookmark candidates
- Every row returned by a query.
- Normal activity with no investigation relevance.
- A result you cannot explain.
- Duplicate evidence already preserved elsewhere.
- Interesting-looking noise that does not answer a case question.
Scenario — the alert starts at 02:08
Our working incident timeline from Lesson 41 begins with suspicious mailbox activity at 02:08.
During a sign-in investigation, you discover this:
The 01:57 event may explain what happened before the first alert. That makes it a strong candidate to preserve.
Preserve the result, not just your memory
Copying a timestamp into a notepad loses context.
A useful bookmark preserves the relevant query result and gives the investigation a route back to the source evidence.
Explain why it matters
Notes should capture the analyst's observation without overstating the evidence.
Example: “Successful sign-in from IP later associated with suspicious mailbox activity. Possible initial access — requires validation.”
Use meaningful names, notes and tags
| Weak | Useful |
|---|---|
| Interesting login | Successful sign-in before mailbox alert — alex@contoso.com |
| Bad IP | 203.0.113.50 observed before suspicious mailbox activity |
| Looks malicious | Possible initial-access event; validate IP ownership and user activity |
| tag: test | tag: initial-access / identity / incident-1234 |
Entity mapping strengthens investigation
Bookmarks can carry mapped entity context such as accounts, hosts, IP addresses and URLs.
Mapped entities make preserved findings more useful for investigation pivots and graphical analysis.
Think about the next analyst
If another analyst opens your bookmark tomorrow, can they understand what you found, why it mattered and what still needs to be tested?
If not, add context.
Bookmarks and the incident timeline
Microsoft Sentinel incident timelines can display both alerts and hunting bookmarks. This means analyst-discovered evidence can sit alongside detection-generated evidence while reconstructing the attack story.
The incident is no longer just a record of what detection rules found. It now contains evidence the investigator discovered as well.
Add evidence to the right incident
Bookmarks can be associated with incidents so important hunting findings remain with the case.
Before attaching one, confirm that the evidence genuinely belongs to that investigation.
A bookmark can broaden the story
A bookmarked result may reveal that activity started earlier, ended later or affected more entities than the original alerts suggested.
When that happens, update your incident hypothesis and timeline.
Return to the source evidence
Microsoft Sentinel lets analysts return from a bookmark to its source query and bookmark logs. This matters because a good investigation must remain reproducible.
Preserve enough context that the evidence can be reviewed, challenged and reproduced by somebody else.
Example hunting query
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
SigninLogs
| where UserPrincipalName =~ "alex@contoso.com"
| where TimeGenerated between (
datetime(2026-10-07 01:30:00) ..
datetime(2026-10-07 02:08:00)
)
| project TimeGenerated, UserPrincipalName, IPAddress,
AppDisplayName, ResultType, ConditionalAccessStatus
| order by TimeGenerated asc
If the 01:57 result materially changes your understanding of the incident, preserve that specific finding with an explanation of why it matters.
Bookmark the evidence — not the whole query
A query may return hundreds of events.
Select the rows that matter to the investigation rather than preserving noise simply because it appeared in the same result set.
Keep hypotheses in context
“Possible initial access” is a useful investigation note.
“Initial access confirmed” should only be written when the supporting evidence actually establishes that conclusion.
Current portal reality
Microsoft currently documents an important transition detail: Sentinel hunting bookmarks can be viewed in the Microsoft Defender portal, but new Sentinel bookmarks are created from the Microsoft Sentinel Hunting experience in the Azure portal.
Bookmarks are also not available in the unified Advanced Hunting experience. Microsoft suggests alternatives such as incident tags, saved queries or custom hunting tables when working there.
Microsoft Sentinel support in the Azure portal ends after 31 March 2027. Learn the evidence-preservation principle as well as today's button locations, because the workflow is changing.
Bookmarks and the classic investigation graph
A bookmark with mapped entities can be investigated visually in the classic investigation graph.
This can help expose relationships between the preserved evidence and other entities or alerts.
Bookmarks can become incidents
During threat hunting, a finding may become serious enough to warrant its own investigation.
Microsoft Sentinel supports using bookmarks to create or enrich incidents, turning a hunting discovery into a formal case.
Evidence quality matters more than bookmark quantity
Common mistake — bookmark everything
More bookmarks do not automatically mean more evidence.
Preserve findings that advance the investigation.
Common mistake — meaningless names
“Suspicious result 1” helps nobody.
Name the finding so another analyst understands what it represents before opening it.
Common mistake — no analyst note
The raw event tells you what happened.
The note should explain why the investigator considered it relevant and what question remains.
Common mistake — bookmark equals malicious
A bookmark records relevance, not guilt.
Continue validating the finding against other evidence.
Agent Foskett investigation exercise
Your incident begins with a mailbox alert at 02:08. Hunting discovers five earlier sign-ins. Four are routine Australian activity. One successful sign-in at 01:57 comes from an unfamiliar address and is followed by the suspicious mailbox activity.
- Decide which result you would bookmark.
- Give the bookmark a meaningful name.
- Write a short analyst note that does not overstate the evidence.
- Identify the entities you would want associated with the finding.
- Explain why the four normal sign-ins do not all need bookmarks.
- Add the preserved finding to the incident timeline.
- State the next query or validation step you would perform.
Best practices
- Bookmark findings that materially advance the case.
- Preserve specific evidence rather than unnecessary result sets.
- Use descriptive names.
- Add concise notes explaining relevance.
- Use tags consistently.
- Preserve useful entity context.
- Attach findings to incidents only when the relationship is supported.
- Keep conclusions separate from hypotheses.
Agent Foskett takeaway
During an investigation, you will find far more data than you can keep in your head.
The skill is not saving everything.
Preserve the evidence that changes the case — and preserve enough context to explain why.
Related Agent Foskett learning
Continue learning
Using Microsoft Sentinel Bookmarks During an Investigation
Microsoft Sentinel hunting bookmarks allow security analysts to preserve important query results and investigation context. Bookmarks can include notes, tags and mapped entities, can be associated with incidents and can appear alongside alerts while analysts reconstruct an incident timeline.
Microsoft Sentinel Lesson 42
This Agent Foskett Microsoft Sentinel Academy lesson teaches analysts when to preserve investigation findings, how to document why a result matters, how bookmarks enrich incident evidence and timelines, and why bookmarking relevant evidence is more useful than saving every unusual query result.
