In this two-hour workshop, participants will experience a full-cycle threat-hunting investigation that blends both active hunting and intelligence analysis. The session begins with a tip-off from a partner company, setting the stage for a targeted hunt. Using Azure Data Explorer (ADX) and Kusto Query Language (KQL), attendees will investigate initial findings, gather relevant intelligence, and learn to understand their adversary by applying the diamond model.