Agent Foskett Academy • Microsoft Sentinel • Module 4 • Lesson 42

Lesson 42 — Using Bookmarks During an Investigation

You run a query and find one event that changes the case.

Then you run another query.

Then another.

Two hours later, can you still find that first event?

That is why investigators preserve evidence.

A bookmark preserves the finding, the query context and the analyst's reason for caring about it.
Agent Foskett preserving investigation evidence with Microsoft Sentinel bookmarks
What you will learn

Preserve the findings that matter without turning the case into a scrapbook.

✓ Know what deserves a bookmark
✓ Preserve query results and context
✓ Add notes, tags and entities
✓ Use bookmarks inside an incident

Learning objectives

  • Explain the operational purpose of a Microsoft Sentinel hunting bookmark.
  • Recognise investigation findings that are worth preserving.
  • Add useful notes, tags and entity context to a bookmark.
  • Use bookmarks to enrich an existing incident and its timeline.
  • Return from a bookmark to its source query and preserved result.
  • Avoid over-bookmarking low-value or unexplained data.

This is not Lesson 15 again

Lesson 15 introduced Microsoft Sentinel bookmarks as a hunting capability.

Now we are inside a live investigation.

The question is no longer “What is a bookmark?”

It is “Which evidence is important enough to preserve?”

What does a bookmark preserve?

Microsoft Sentinel hunting bookmarks preserve query results that an analyst considers relevant. They can also retain contextual observations through notes and tags, helping analysts and teammates return to important findings later.

KQL QUERY │ ▼ 500 RESULTS │ ├── normal ├── normal ├── normal ├── SUSPICIOUS EVENT ◄── preserve this ├── normal └── normal │ ▼ BOOKMARK │ ┌──────┼──────┐ ▼ ▼ ▼ Result Notes Tags │ ▼ Investigation

A bookmark is not an alert

An alert is normally generated because detection logic matched defined conditions.

A bookmark is an analyst-preserved finding. It records something the investigator decided was worth keeping.

A bookmark is not a conclusion

Saving a result does not make it malicious.

A bookmark may represent suspicious activity, a possible root cause, an indicator, a useful pivot or simply evidence that needs further investigation.

The Agent Foskett bookmark test

You found an interesting result │ ▼ Will it help explain the incident? │ ┌─────┴─────┐ │ │ YES NO │ │ ▼ ▼ Would another Keep analyst need it? investigating │ ▼ Can you explain WHY it matters? │ ├── NO → investigate first │ └── YES │ ▼ BOOKMARK

Good bookmark candidates

  • A suspicious event that predates the first alert.
  • A possible initial-access event.
  • A newly discovered indicator of compromise.
  • A persistence or privilege change.
  • An event connecting two previously separate entities.
  • A result that materially changes incident scope.

Poor bookmark candidates

  • Every row returned by a query.
  • Normal activity with no investigation relevance.
  • A result you cannot explain.
  • Duplicate evidence already preserved elsewhere.
  • Interesting-looking noise that does not answer a case question.

Scenario — the alert starts at 02:08

Our working incident timeline from Lesson 41 begins with suspicious mailbox activity at 02:08.

During a sign-in investigation, you discover this:

01:57 Successful sign-in User: alex@contoso.com IP: 203.0.113.50 App: Microsoft Office Result: Success 02:08 Suspicious mailbox activity alert 02:14 Suspicious PowerShell 02:17 Malicious network connection

The 01:57 event may explain what happened before the first alert. That makes it a strong candidate to preserve.

Preserve the result, not just your memory

Copying a timestamp into a notepad loses context.

A useful bookmark preserves the relevant query result and gives the investigation a route back to the source evidence.

Explain why it matters

Notes should capture the analyst's observation without overstating the evidence.

Example: “Successful sign-in from IP later associated with suspicious mailbox activity. Possible initial access — requires validation.”

Use meaningful names, notes and tags

WeakUseful
Interesting loginSuccessful sign-in before mailbox alert — alex@contoso.com
Bad IP203.0.113.50 observed before suspicious mailbox activity
Looks maliciousPossible initial-access event; validate IP ownership and user activity
tag: testtag: initial-access / identity / incident-1234

Entity mapping strengthens investigation

Bookmarks can carry mapped entity context such as accounts, hosts, IP addresses and URLs.

Mapped entities make preserved findings more useful for investigation pivots and graphical analysis.

Think about the next analyst

If another analyst opens your bookmark tomorrow, can they understand what you found, why it mattered and what still needs to be tested?

If not, add context.

Bookmarks and the incident timeline

Microsoft Sentinel incident timelines can display both alerts and hunting bookmarks. This means analyst-discovered evidence can sit alongside detection-generated evidence while reconstructing the attack story.

01:57 BOOKMARK — suspicious sign-in │ 02:08 ALERT — mailbox manipulation │ 02:14 ALERT — PowerShell execution │ 02:17 ALERT — malicious connection │ 02:31 BOOKMARK — second affected device

The incident is no longer just a record of what detection rules found. It now contains evidence the investigator discovered as well.

Add evidence to the right incident

Bookmarks can be associated with incidents so important hunting findings remain with the case.

Before attaching one, confirm that the evidence genuinely belongs to that investigation.

A bookmark can broaden the story

A bookmarked result may reveal that activity started earlier, ended later or affected more entities than the original alerts suggested.

When that happens, update your incident hypothesis and timeline.

Return to the source evidence

Microsoft Sentinel lets analysts return from a bookmark to its source query and bookmark logs. This matters because a good investigation must remain reproducible.

Do not preserve only the conclusion.

Preserve enough context that the evidence can be reviewed, challenged and reproduced by somebody else.

Example hunting query

Find pre-alert sign-in activity
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
SigninLogs
| where UserPrincipalName =~ "alex@contoso.com"
| where TimeGenerated between (
    datetime(2026-10-07 01:30:00) ..
    datetime(2026-10-07 02:08:00)
)
| project TimeGenerated, UserPrincipalName, IPAddress,
          AppDisplayName, ResultType, ConditionalAccessStatus
| order by TimeGenerated asc

If the 01:57 result materially changes your understanding of the incident, preserve that specific finding with an explanation of why it matters.

Bookmark the evidence — not the whole query

A query may return hundreds of events.

Select the rows that matter to the investigation rather than preserving noise simply because it appeared in the same result set.

Keep hypotheses in context

“Possible initial access” is a useful investigation note.

“Initial access confirmed” should only be written when the supporting evidence actually establishes that conclusion.

Current portal reality

Microsoft currently documents an important transition detail: Sentinel hunting bookmarks can be viewed in the Microsoft Defender portal, but new Sentinel bookmarks are created from the Microsoft Sentinel Hunting experience in the Azure portal.

Bookmarks are also not available in the unified Advanced Hunting experience. Microsoft suggests alternatives such as incident tags, saved queries or custom hunting tables when working there.

Why this matters:

Microsoft Sentinel support in the Azure portal ends after 31 March 2027. Learn the evidence-preservation principle as well as today's button locations, because the workflow is changing.

Bookmarks and the classic investigation graph

A bookmark with mapped entities can be investigated visually in the classic investigation graph.

This can help expose relationships between the preserved evidence and other entities or alerts.

Bookmarks can become incidents

During threat hunting, a finding may become serious enough to warrant its own investigation.

Microsoft Sentinel supports using bookmarks to create or enrich incidents, turning a hunting discovery into a formal case.

Evidence quality matters more than bookmark quantity

20 RANDOM BOOKMARKS ≠ STRONG INVESTIGATION 3 WELL-DOCUMENTED FINDINGS + CLEAR QUERY CONTEXT + MAPPED ENTITIES + USEFUL NOTES = DEFENSIBLE EVIDENCE

Common mistake — bookmark everything

More bookmarks do not automatically mean more evidence.

Preserve findings that advance the investigation.

Common mistake — meaningless names

“Suspicious result 1” helps nobody.

Name the finding so another analyst understands what it represents before opening it.

Common mistake — no analyst note

The raw event tells you what happened.

The note should explain why the investigator considered it relevant and what question remains.

Common mistake — bookmark equals malicious

A bookmark records relevance, not guilt.

Continue validating the finding against other evidence.

Agent Foskett investigation exercise

Scenario:

Your incident begins with a mailbox alert at 02:08. Hunting discovers five earlier sign-ins. Four are routine Australian activity. One successful sign-in at 01:57 comes from an unfamiliar address and is followed by the suspicious mailbox activity.

  1. Decide which result you would bookmark.
  2. Give the bookmark a meaningful name.
  3. Write a short analyst note that does not overstate the evidence.
  4. Identify the entities you would want associated with the finding.
  5. Explain why the four normal sign-ins do not all need bookmarks.
  6. Add the preserved finding to the incident timeline.
  7. State the next query or validation step you would perform.

Best practices

  • Bookmark findings that materially advance the case.
  • Preserve specific evidence rather than unnecessary result sets.
  • Use descriptive names.
  • Add concise notes explaining relevance.
  • Use tags consistently.
  • Preserve useful entity context.
  • Attach findings to incidents only when the relationship is supported.
  • Keep conclusions separate from hypotheses.

Agent Foskett takeaway

During an investigation, you will find far more data than you can keep in your head.

The skill is not saving everything.

Preserve the evidence that changes the case — and preserve enough context to explain why.

Lesson summary
Microsoft Sentinel bookmarks help investigators preserve important query results, notes, tags and entity context discovered during hunting and investigation. Used carefully, they enrich the incident timeline, support collaboration and make important findings reproducible without burying the case in low-value evidence.
Sentinel Academy Home

Continue learning

Module 4 — Incidents and Investigation.
⬅ Previous lesson
Lesson 41 — Building an Incident TimelineReview how alerts, entities and raw telemetry become an evidence-based chronology.
🏠 Academy home
Microsoft Sentinel AcademyBrowse all available Sentinel lessons and modules.
Next lesson ➡
Lesson 43 — Adding Evidence and Investigation NotesLearn how to document findings, reasoning, evidence and unanswered questions so another analyst can understand and continue the case.

Using Microsoft Sentinel Bookmarks During an Investigation

Microsoft Sentinel hunting bookmarks allow security analysts to preserve important query results and investigation context. Bookmarks can include notes, tags and mapped entities, can be associated with incidents and can appear alongside alerts while analysts reconstruct an incident timeline.

Microsoft Sentinel Lesson 42

This Agent Foskett Microsoft Sentinel Academy lesson teaches analysts when to preserve investigation findings, how to document why a result matters, how bookmarks enrich incident evidence and timelines, and why bookmarking relevant evidence is more useful than saving every unusual query result.