Access Microsoft Defender Advanced Hunting shared queries programmatically

Owen Davey 0 Reputation points
2025-10-30T15:17:21.7666667+00:00

I am trying to automate the creation and management of Advanced Hunting queries for use in the Microsoft Defender portal under the "Investigation & Response -> Hunting -> Advanced Hunting" sidebar items.

There are APIs provided by Azure Management but they only seem to return (or create) the queries under the Microsoft Sentinel folder in that area.

Any queries created outside of the "Microsoft Sentinel" folder are not visible on the APIs.

The picture below highlights the issue. The API's only can return the queries in the RED box. I am unable to see any of the queries with green arrows next to them.

DefenderAdvancedHunting

The API being used is: Saved Searches - List By Workspace and its ARM counterpart Microsoft.OperationalInsights workspaces/savedSearches

Using these I am unable to access any query outside the "Microsoft Sentinel" folder.

I have checked both the Defender API (depreciated) and Graph API and neither have endpoints documented that return this data.

Is there some secret endpoint or query string I can use to access these Defender based items.

Outside the scope of this immediate question - I have the same issue with many of the APIs. I am unable to see analytic rules, tuned alerts automation, etc. that were created inside Defender. It is tempting to just use Sentinel for everything - but the Sentinel portal is being depreciated. This leaves me in a poor situation.

Microsoft Security | Microsoft Defender | Other
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.