---
title: Take actions from Threat Hunting in M365 Defender
description: We wrote a blog post earlier about the news in threat huntingNew features in Advanced Hunting – Microsoft 365 Defender – SEC-LABS R&amp;DAnother feature in hunting, which will speed up respo...
---

[Onevinn blog ](https://www.onevinn.com/blog)

# [Take actions from Threat Hunting in M365 Defender](https://www.onevinn.com/blog/take-actions-from-threat-hunting-in-m365-defender)

 Written by [SEC-LABS R&D](https://www.onevinn.com/blog/author/sec-labs-rd) | 07 Oct 2022

We wrote a blog post earlier about the news in threat hunting

[New features in Advanced Hunting – Microsoft 365 Defender – SEC-LABS R&D](https://blog.sec-labs.com/2021/11/new-features-in-advanced-hunting-microsoft-365-defender/)

Another feature in hunting, which will speed up responses from a threat hunting scenario is ***Take*** ***Action***

When selecting a record in the result, the ***Take Action*** button will be visible as seen in below picture

So instead of just creating a new incident or adding events to an existing incident we can take actions from the hunting experience.

In the Take actions experience we have actions grouped by Devices, Files and Users.

The action options available is dependent on the data in the result. For instance, file information like checksum is required to being able to quarantine a file.

When clicking Next we can see the target selected and click Next

We can add a Remediation name and Description for our action

This feature enables a rapid response at the fingertips of the threat hunters for immediate actions

***For further information, please visit***

[https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-take-action?view=o365-worldwide](https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-take-action?view=o365-worldwide&WT.mc_id=ES-MVP-5003832)

Happy Hunting!

Sec-Labs Team

[View full post](https://www.onevinn.com/blog/take-actions-from-threat-hunting-in-m365-defender)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SEC-LABS R&D"
  },
  "dateModified" : "2022-10-07T06:00:00.478Z",
  "datePublished" : "2022-10-07T06:00:00Z",
  "headline" : "Take actions from Threat Hunting in M365 Defender",
  "image" : {
    "@type" : "ImageObject",
    "height" : 60,
    "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
    "width" : 60
  },
  "mainEntityOfPage" : "https://www.onevinn.com/blog/take-actions-from-threat-hunting-in-m365-defender",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Onevinn blog"
  }
}
```