⚠️ Egress Defend

⚠️ Unpublished: This item is from a solution that is not yet published on Azure Marketplace or not installed in Content Hub.

Egress Defend Logo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index


Attribute Value
Publisher egress1589289169584
Support Tier Partner
Support Link https://support.egress.com/s/
Categories Application
Version 3.1.0
Author Egress - support@egress.com
First Published 2023-07-27
Solution Folder Egress Defend

Egress Defend for Microsoft Sentinel provides details of processed emails, including the type of phishing attack, payload type and information to show if the user interacted with the email in a positive (clicking on banners or submitting the phish sample) or negative (clicking on an unsafe URL) manner.

Contents

Data Connectors

This solution provides 2 data connector(s):

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 3 table(s):

Table Used By Connectors Used By Content
EgressDefend_CL 🔶 Egress Defend Analytics, Hunting, Workbooks
EgressDefend_v4_CL 🔶 Egress Defend v2 Analytics, Hunting, Workbooks
KnowBe4Defend_CL 🔶 Egress Defend -

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 6 content item(s) (5 in solution, 1 discovered 🔍):

Content Type Total In Solution Discovered
Analytic Rules 2 2 -
Parsers 2 1 1
Hunting Queries 1 1 -
Workbooks 1 1 -

Analytic Rules

Name Severity Tactics Tables Used
Egress Defend - Dangerous Attachment Detected Medium Execution, InitialAccess, Persistence, PrivilegeEscalation EgressDefend_CL
EgressDefend_v4_CL
Egress Defend - Dangerous Link Click Medium Execution EgressDefend_CL
EgressDefend_v4_CL

Hunting Queries

Name Tactics Tables Used
Dangerous emails with links clicked Collection EgressDefend_CL
EgressDefend_v4_CL

Workbooks

Name Tables Used
DefendMetrics EgressDefend_CL
EgressDefend_v4_CL

Parsers

Name Description Tables Used
DefendAuditData ⚠️ - EgressDefend_CL (read)
DefendAuditData_v4 - EgressDefend_CL (read)
EgressDefend_v4_CL (read)

⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.1.0 01-09-2026 Added a new Data Connector using the Logs Ingestion API (CCF RestApiPoller with DCR/DCE), replacing the retiring HTTP Data Collector API. Added a new Parser DefendAuditData_v4. Updated Analytic Rules, Workbook and Hunting Query to read from DefendAuditData_v4. The original connector, table and parser are unchanged, so existing installations keep working until the new connector is enabled.
3.0.0 02-08-2023 Initial Solution Release.

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Solutions Index