⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
| Attribute | Value |
|---|---|
| Publisher | egress1589289169584 |
| Support Tier | Partner |
| Support Link | https://support.egress.com/s/ |
| Categories | Application |
| Version | 3.1.0 |
| Author | Egress - support@egress.com |
| First Published | 2023-07-27 |
| Solution Folder | Egress Defend |
Egress Defend for Microsoft Sentinel provides details of processed emails, including the type of phishing attack, payload type and information to show if the user interacted with the email in a positive (clicking on banners or submitting the phish sample) or negative (clicking on an unsafe URL) manner.
This solution provides 2 data connector(s):
🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution uses 3 table(s):
| Table | Used By Connectors | Used By Content |
|---|---|---|
EgressDefend_CL 🔶 |
Egress Defend | Analytics, Hunting, Workbooks |
EgressDefend_v4_CL 🔶 |
Egress Defend v2 | Analytics, Hunting, Workbooks |
KnowBe4Defend_CL 🔶 |
Egress Defend | - |
🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g.
_s,_d,_b,_t,_g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.
This solution includes 6 content item(s) (5 in solution, 1 discovered 🔍):
| Content Type | Total | In Solution | Discovered |
|---|---|---|---|
| Analytic Rules | 2 | 2 | - |
| Parsers | 2 | 1 | 1 |
| Hunting Queries | 1 | 1 | - |
| Workbooks | 1 | 1 | - |
| Name | Severity | Tactics | Tables Used |
|---|---|---|---|
| Egress Defend - Dangerous Attachment Detected | Medium | Execution, InitialAccess, Persistence, PrivilegeEscalation | EgressDefend_CLEgressDefend_v4_CL |
| Egress Defend - Dangerous Link Click | Medium | Execution | EgressDefend_CLEgressDefend_v4_CL |
| Name | Tactics | Tables Used |
|---|---|---|
| Dangerous emails with links clicked | Collection | EgressDefend_CLEgressDefend_v4_CL |
| Name | Tables Used |
|---|---|
| DefendMetrics | EgressDefend_CLEgressDefend_v4_CL |
| Name | Description | Tables Used |
|---|---|---|
| DefendAuditData ⚠️ | - | EgressDefend_CL (read) |
| DefendAuditData_v4 | - | EgressDefend_CL (read)EgressDefend_v4_CL (read) |
⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.
| Version | Date Modified (DD-MM-YYYY) | Change History |
|---|---|---|
| 3.1.0 | 01-09-2026 | Added a new Data Connector using the Logs Ingestion API (CCF RestApiPoller with DCR/DCE), replacing the retiring HTTP Data Collector API. Added a new Parser DefendAuditData_v4. Updated Analytic Rules, Workbook and Hunting Query to read from DefendAuditData_v4. The original connector, table and parser are unchanged, so existing installations keep working until the new connector is enabled. |
| 3.0.0 | 02-08-2023 | Initial Solution Release. |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊