KQL - User Security Alert & Incident History

Correlates Microsoft Sentinel Security Alerts and Security Incidents associated with a specific user account over a 90-day period. The query identifies medium and high-severity alerts, maps them to their corresponding incidents, and provides investigation outcomes including classification, closure details, and ownership information. This detection enables analysts to quickly understand a user's historical security exposure, determine whether previous incidents were resolved appropriately, and identify patterns of recurring security activity.

Microsoft Sentinel (KQL)