Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Microsoft 365 email events, including email delivery and blocking events
| Attribute | Value |
|---|---|
| Category | Defender |
| Basic Logs Eligible | ✓ Yes (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✗ No |
| Lake-Only Ingestion | ✓ Yes (source) |
| Azure Monitor Tables Reference | View Documentation |
| Defender XDR Advanced Hunting Schema | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| AdditionalFields | dynamic | Additional information about the entity or event. |
| AttachmentCount | int | Number of attachments in the email. |
| AuthenticationDetails | string | List of pass or fail verdicts by email authentication protocols like DMARC, DKIM, SPF or a combination of multiple authentication types (CompAuth). |
| BulkComplaintLevel | int | Threshold assigned to email from bulk mailers, a high bulk complaint level (BCL) means the email is more likely to generate complaints, and thus more likely to be spam. |
| Cc | dynamic | Indicates the addresses which are listed in Cc fields of an email |
| ConfidenceLevel | string | List of confidence levels of any spam or phishing verdicts. For spam, this column shows the spam confidence level (SCL), indicating if the email was skipped (-1), found to be not spam (0,1), found to be spam with moderate confidence (5,6), or found to be spam with high confidence (9). For phishing, this column displays whether the confidence level is "High" or "Low". |
| Connectors | string | Custom instructions that define organizational mail flow and how the email was routed. |
| Context | string | Configuration context data of the machine |
| DeliveryAction | string | Action of the delivered email. |
| DeliveryLocation | string | Location of the delivered email: Inbox/Folder, On-premises/External, Junk, Quarantine, Failed, Dropped, Deleted items. |
| DetectionMethods | string | Delivery action of the email: Delivered, Junked, Blocked, or Replaced. |
| DistributionList | string | Name of distribution list that the recipient was a member of and to which the email was sent, if applicable; shows top-level distribution list if nested lists are involved |
| EmailAction | string | Final action taken on the email based on filter verdict, policies, and user actions: Move message to junk mail folder, Add X-header, Modify subject, Redirect message, Delete message, send to quarantine, No action taken, Bcc message. |
| EmailActionPolicy | string | Action policy that took effect: Antispam high-confidence, Antispam, Antispam bulk mail, Antispam phishing, Anti-phishing domain impersonation, Anti-phishing user impersonation, Anti-phishing spoof, Anti-phishing graph impersonation, Antimalware Safe Attachments, Enterprise Transport Rules (ETR). |
| EmailActionPolicyGuid | string | Unique identifier of the policy that took effect. |
| EmailClusterId | long | Identifier of the email cluster. Emails are clustered (grouped) based on heuristic analysis of their contents. |
| EmailDirection | string | Email direction: Inbound, Outbound, Intra-org. |
| EmailLanguage | string | Detected language of the email content. |
| EmailSize | int | Size of the email message. |
| ExchangeTransportRule | string | Mail flow rules (also known as transport rules) are similar to Inbox rules that are available in Outlook and Outlook on the web. The main difference is mail flow rules take action on messages while they're in transit. |
| ForwardingInformation | string | A JSON array of forwarding details including the forwarding user and the forwarding type |
| InternetMessageId | string | Public-facing identifier for the email that is set by the sending email system. |
| IsFirstContact | bool | Is this the first contact between sender and reciever. |
| LastEventExecutionTime | datetime | Date and time (UTC) when the record was updated post merge. |
| LatestDeliveryAction | string | Last known action attempted on an email by the service or by an admin through manual remediation. |
| LatestDeliveryLocation | string | Last known location of the email. |
| NetworkMessageId | string | Unique identifier for the email, generated by Office 365. |
| OrgLevelAction | string | Action taken on the email in response to matches to a policy defined at the organizational level. |
| OrgLevelPolicy | string | Organizational policy that triggered the action taken on the email. |
| RecipientDomain | string | Domain of the recipient of the email. |
| RecipientEmailAddress | string | Recipient email address or email address of the recipient after distribution list expansion. |
| RecipientObjectId | string | Email recipient Azure AD identifier. |
| ReportId | string | Unique identifier for the event. |
| SenderDisplayName | string | Sender email address in the from header, which is visible to email recipients on their email clients. |
| SenderFromAddress | string | Sender domain in the from header, which is visible to email recipients on their email clients. |
| SenderFromDomain | string | Verdict from the email filtering stack on whether the email contains malware, phishing, or other threats. |
| SenderIPv4 | string | IPv4 address of the last detected mail server that relayed the message. |
| SenderIPv6 | string | IPv6 address of the last detected mail server that relayed the message. |
| SenderMailFromAddress | string | Sender email address in the MAIL from header, also known as the envelope sender or the Return-Path address. |
| SenderMailFromDomain | string | Sender domain in the MAIL from header, also known as the envelope sender or the Return-Path address. |
| SenderObjectId | string | Sender email address in the from header, which is visible to email recipients on their email clients. |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| Subject | string | Email subject field. |
| TenantId | string | The Log Analytics workspace ID |
| ThreatClassification | string | Indicates the threat classification of the mail |
| ThreatNames | string | Sender email address in the from header, which is visible to email recipients on their email clients. |
| ThreatTypes | string | Verdict from the email filtering stack on whether the email contains malware, phishing, or other threats. |
| TimeGenerated | datetime | Date and time (UTC) when the record was generated. |
| To | dynamic | Indicates the addresses which are listed in To fields of an email |
| Type | string | The name of the table |
| UrlCount | int | Number of embedded URLs in the email. |
| UserLevelAction | string | Action taken on the email in response to matches to a mailbox policy defined by the recipient. |
| UserLevelPolicy | string | End user mailbox policy that triggered the action taken on the email. |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Microsoft Defender XDR |
In solution Microsoft Business Applications: EmailDirection == "Outbound"
| Analytic Rule |
|---|
| Dataverse - Terminated employee exfiltration over email |
In solution Threat Intelligence:
| Analytic Rule | Selection Criteria |
|---|---|
| TI Map URL Entity to EmailUrlInfo | |
| TI map Domain entity to EmailEvents | |
| TI map Domain entity to EmailUrlInfo | DeliveryAction !has "Blocked" |
| TI map Email entity to EmailEvents |
In solution Threat Intelligence (NEW):
| Analytic Rule | Selection Criteria |
|---|---|
| TI Map Domain entity to EmailEvents | |
| TI Map Domain entity to EmailUrlInfo | DeliveryAction !has "Blocked" |
| TI Map Email entity to EmailEvents | |
| TI Map URL Entity to EmailUrlInfo |
Standalone Content:
| Analytic Rule | Selection Criteria |
|---|---|
| Star Blizzard C2 Domains August 2022 |
In solution Business Email Compromise - Financial Fraud:
| Hunting Query | Selection Criteria |
|---|---|
| Email Forwarding Configuration with SAP download |
In solution Microsoft Defender XDR:
| Hunting Query | Selection Criteria |
|---|---|
| Automated Remediation Delivery to Action Latency | ActionType == "Automated Remediation" |
| Automated email notifications and suspicious sign-in activity | |
| Automatic External Email Forwarding Overview by Type (Mailbox Rule and SMTP) | EmailDirection == "Outbound" |
| Bad email percentage of Inbound emails | EmailDirection == "Inbound" |
| Bulk Emails by Sender Bulk Complaint level | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Calculate overall MDO efficacy | |
| CompAuth Failure Trend | |
| DKIM Failure Trend | |
| DMARC Failure Trend | |
| Determine Successfully Delivered Phishing Emails by top IP Addresses | DeliveryAction == "Delivered"ThreatTypes has "Malware"ThreatTypes has "Phish" |
| Determine Successfully Delivered Phishing Emails to Inbox/Junk folder. | DeliveryLocation in "Inbox/folder,Junk folder" |
| Email Top 10 Domains sending Spam | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Email Top 10 Targeted Users (Spam) | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Email Top 15 Domains sending Spam with Additional Details | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Email Top 15 Targeted Users (Spam) with Additional Details | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Email Top Domains sending Malware | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Email Top Domains sending Phish | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Email bombing attacks | DeliveryAction == "Delivered" |
| Files share contents and suspicious sign-in activity | |
| First-Contact External Email Senders | EmailDirection == "Inbound" |
| Hunt for email bombing attacks | EmailDirection == "Inbound" |
| Impersonation Detections Trend | DetectionMethods has "Impersonation" |
| Impersonation Detections by Detection Technology | DetectionMethods has "Impersonation" |
| Impersonation Detections by Detection Technology Trend | |
| Impersonation and Spoof Detections by Sender Country | DetectionMethods has "Impersonation"DetectionMethods has "Spoof"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
| Inbound Sender Domains Failing Email Authentication | EmailDirection == "Inbound"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
| Largest Malicious Email Campaigns by Cluster | EmailDirection == "Inbound"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
| MDO Threat Protection Detections trend over time | |
| Malicious Email Campaigns by Recipient URL Clicks | EmailDirection == "Inbound"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
| Malware Detection IP and Geo Position | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Malware Detections Trend | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Malware Detections by Detection technology | DetectionMethods has "Malware"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Malware Detections by Detection technology Trend | DetectionMethods has "Malware"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Malware Detections by Sender Country | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Malware Detections by Threat Classification | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Malware Detections by delivery location | DeliveryLocation in "Failed,Quarantine"DetectionMethods has "Malware"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Malware URL Detections Trend | DetectionMethods has "Malware"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Message from an Accepted Domain with DMARC TempError | EmailDirection == "Inbound" |
| New External Sender Domains Carrying Threats | EmailDirection == "Inbound" |
| Phish Detection IP and Geo Position | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Phish Detections (High) by delivery location | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Phish Detections (Normal) by delivery location | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Phish Detections Trend | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Phish Detections by Detection technology | DetectionMethods has "Phish"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Phish Detections by Detection technology Trend | DetectionMethods has "Phish"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Phish Detections by Sender Country | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Phish Detections by Threat Classification | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Phish Detections by delivery location trend | DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"DetectionMethods has "Phish"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Phishing Detected by LLM Content Analysis | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Phishing URL Detections Trend | DetectionMethods has "Phish"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| QR Code URL Detections Trend | DetectionMethods has "Url"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Quarantine Malware Reason | DeliveryLocation == "Quarantine"DetectionMethods has "Malware"EmailDirection == "Inbound" |
| Quarantine Phish Reason | DeliveryLocation == "Quarantine"DetectionMethods has "Phish"EmailDirection == "Inbound" |
| Quarantine Phish Reason trend | DeliveryLocation == "Quarantine"DetectionMethods has "Phish"EmailDirection == "Inbound" |
| Quarantine Release Percentage | |
| Quarantine Spam Reason | DeliveryLocation == "Quarantine"DetectionMethods has "Spam"EmailDirection == "Inbound" |
| Quarantine Spam Reason trend | DeliveryLocation == "Quarantine"DetectionMethods has "Spam"EmailDirection == "Inbound" |
| Quarantine releases by Detection Types | |
| SPF Failure Trend | |
| SecOps Mailbox Override Count | OrgLevelAction == "Allow"OrgLevelPolicy == "SecOps Mailbox" |
| SecOps Mailbox Overrides by Threat Type | OrgLevelAction == "Allow"OrgLevelPolicy == "SecOps Mailbox" |
| Spam Detections (High) by delivery location | ConfidenceLevel has_any "Spam"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Spam Detections (Normal) by delivery location | ConfidenceLevel has_any "Spam"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Spam Detections by Detection technology | DetectionMethods has "Spam"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Spam Detections by Sender Country | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Spam and Phish allowed to inbox by Admin Overrides | |
| Spam and Phish allowed to inbox by User Overrides | |
| Spam detection by IP and its location | |
| Spam detection by delivery location | DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"DetectionMethods has "Spam"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Spam detection technologies | DetectionMethods has "Spam"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Spam detection trend | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Spoof Detections Trend | DetectionMethods has "Spoof" |
| Spoof Detections by Detection Technology | DetectionMethods has "Spoof" |
| Spoof Detections by Detection Technology Trend | |
| Spoofing attempts from Specific Domains | DetectionMethods has "spoof" |
| Suspicious Microsoft Teams Callers by Impersonation-Style Identity | |
| Top 10 External Senders (Spam) | EmailDirection == "Inbound"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Spam" |
| Top 10 domains sending Bulk email | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Top 10 sender domains - Admin email submissions (FN) | |
| Top Attacked Users by Malware Threat Classification | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Top Attacked Users by Phish Threat Classification | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Top Domains Outbound with Emails with Threats Inbound (Partner BEC) | EmailDirection in "Inbound,Outbound" |
| Top External Domains Receiving Auto-forwarded Email (Mailbox Rule and SMTP) | EmailDirection == "Outbound" |
| Top External Recipients Receiving Auto-forwarded Email (Mailbox Rule and SMTP) | EmailDirection == "Outbound" |
| Top Internal Users Auto-forwarding Email Externally (Mailbox Rule and SMTP) | EmailDirection == "Outbound" |
| Top Malware Families | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Top Recipients Receiving Threats Delivered by Override | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Top Recipients Targeted by Impersonation or BEC | DeliveryLocation has "Inbox"DetectionMethods has "Impersonation"EmailDirection == "Inbound"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
| Top Sender Domains Delivering Threats via Override | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Top Spoof DMARC detections by Sender domain (P1/P2) | EmailDirection == "Inbound" |
| Top Spoof external domain detections by Sender domain (P1/P2) | EmailDirection == "Inbound" |
| Top Spoof intra-org detections by Sender domain (P1/P2) | EmailDirection == "Inbound" |
| Top Users receiving Malware | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Top Users receiving Phish | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Top outbound recipient domains sending inbound emails with threats | EmailDirection in "Inbound,Outbound" |
| Total Emails with Admin Overrides (Allow) | OrgLevelAction == "Allow" |
| Total Emails with Admin Overrides (Block) | OrgLevelAction == "Block" |
| Total Emails with User Overrides (Allow) | UserLevelAction == "Allow" |
| Total Emails with User Overrides (Block) | UserLevelAction == "Block" |
| Total number of detections by MDO | |
| User Email Submissions (FN) - Top Inbound P2 Senders | EmailDirection == "Inbound" |
| User Email Submissions (FN) - Top Inbound P2 Senders domains | EmailDirection == "Inbound" |
| User Email Submissions (FP) - Top Inbound P2 Senders | ActionType == "UserSubmission"EmailDirection == "Inbound" |
| User Email Submissions (FP) - Top Inbound Subjects | ActionType == "UserSubmission"EmailDirection == "Inbound" |
| User Email Submissions (FP) - Top Intra-Org P2 Senders | ActionType == "UserSubmission"EmailDirection == "Intra-org" |
| User Submissions by Detection Method - Phish (FP) | ActionType == "UserSubmission"DetectionMethods has "Phish"EmailDirection == "Inbound" |
| User Submissions by Detection Method - Spam (FP) | ActionType == "UserSubmission"DetectionMethods has "Spam"EmailDirection == "Inbound" |
| Zero-day Malware Detections Trend | DetectionMethods has "Malware"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Zero-day Phish Detections Trend | DetectionMethods has "Phish"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
Standalone Content: DeliveryAction == "Delivered"EmailDirection == "Inbound"
| Hunting Query |
|---|
| Raw IP Address Used as URL Domain |
GitHub Only:
| Hunting Query | Selection Criteria |
|---|---|
| Attacked more than x times average | |
| Attacked more than x times average | |
| Authentication failures by time and authentication type | |
| Authentication failures by time and authentication type | |
| Automated Remediation Delivery to Action Latency | ActionType == "Automated Remediation" |
| Automated email notifications and suspicious sign-in activity | |
| Automatic External Email Forwarding Overview by Type (Mailbox Rule and SMTP) | EmailDirection == "Outbound" |
| Bad email percentage of Inbound emails | EmailDirection == "Inbound" |
| Bazacall Emails | |
| Bulk Emails by Sender Bulk Complaint level | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Calculate overall MDO efficacy | |
| Campaign with suspicious keywords | DeliveryAction == "Delivered"EmailDirection == "Inbound" |
| Campaign with suspicious keywords | DeliveryAction == "Delivered"EmailDirection == "Inbound" |
| CompAuth Failure Trend | |
| Custom detection-Emails with QR from non-prevalent senders | |
| Custom detection-Emails with QR from non-prevalent senders | |
| DKIM Failure Trend | |
| DMARC Failure Trend | |
| Detections by detection methods | |
| Detections by detection methods | |
| Display Name - Spoof and Impersonation | DeliveryAction == "Delivered"EmailDirection == "Inbound"OrgLevelAction != "Block"SenderDisplayName contains "Microsoft"UserLevelAction != "Block" |
| Display Name - Spoof and Impersonation | DeliveryAction == "Delivered"EmailDirection == "Inbound"OrgLevelAction != "Block"SenderDisplayName contains "Microsoft"UserLevelAction != "Block" |
| Email Top 10 Domains sending Spam | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Email Top 10 Targeted Users (Spam) | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Email Top 15 Domains sending Spam with Additional Details | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Email Top 15 Targeted Users (Spam) with Additional Details | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Email Top Domains sending Malware | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Email Top Domains sending Phish | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Email bombing attacks | DeliveryAction == "Delivered" |
| Email containing malware sent by an internal sender | EmailDirection in "Intra-org,Outbound"SenderFromAddress !startswith "microsoftexchange"SenderFromAddress !startswith "postmaster@"ThreatTypes == "Malware" |
| Email containing malware sent by an internal sender | EmailDirection in "Intra-org,Outbound"SenderFromAddress !startswith "microsoftexchange"SenderFromAddress !startswith "postmaster@"ThreatTypes == "Malware" |
| Email malware detection report | |
| Email malware detection report | |
| Email sender IP address Geo location information | |
| Email sender IP address Geo location information | |
| Emails delivered having URLs from QR codes | DeliveryAction == "Delivered"EmailDirection == "Inbound" |
| Emails delivered having URLs from QR codes | DeliveryAction == "Delivered"EmailDirection == "Inbound" |
| Emails with QR codes and suspicious keywords in subject | DeliveryAction == "Delivered"EmailDirection == "Inbound" |
| Emails with QR codes and suspicious keywords in subject | DeliveryAction == "Delivered"EmailDirection == "Inbound" |
| Emails with QR codes from non-prevalent sender | |
| Emails with QR codes from non-prevalent sender | |
| Empty Sender Phish Delivered to Inbox | DeliveryAction != "Blocked"EmailDirection == "Inbound"SenderIPv4 startswith "27.121.5."SenderMailFromAddress == "<>" |
| Fake Replies | EmailDirection == "Inbound"Subject startswith "RE:" |
| First-Contact External Email Senders | EmailDirection == "Inbound" |
| Good emails from senders with bad patterns | EmailDirection == "Inbound" |
| Good emails from senders with bad patterns | EmailDirection == "Inbound" |
| High Confidence Phish Released | |
| High Confidence Phish Released | |
| Hunt for email bombing attacks | EmailDirection == "Inbound" |
| Hunt for email conversation take over attempts | DeliveryLocation != "Quarantine"EmailDirection == "Inbound"OrgLevelAction != "Block"UserLevelAction != "Block" |
| Hunt for email conversation take over attempts | DeliveryLocation != "Quarantine"EmailDirection == "Inbound"OrgLevelAction != "Block"UserLevelAction != "Block" |
| Hunting for sender patterns | |
| Hunting for sender patterns | |
| Hunting for user signals-clusters | EmailDirection == "Inbound" |
| Hunting for user signals-clusters | EmailDirection == "Inbound" |
| IcedId attachments | AttachmentCount == "1"EmailDirection == "Inbound" |
| Impersonation Detections Trend | DetectionMethods has "Impersonation" |
| Impersonation Detections by Detection Technology | DetectionMethods has "Impersonation" |
| Impersonation Detections by Detection Technology Trend | |
| Impersonation and Spoof Detections by Sender Country | DetectionMethods has "Impersonation"DetectionMethods has "Spoof"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
| Inbound Sender Domains Failing Email Authentication | EmailDirection == "Inbound"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
| Inbound emails with QR code URLs | EmailDirection == "Inbound" |
| Inbound emails with QR code URLs | EmailDirection == "Inbound" |
| Largest Malicious Email Campaigns by Cluster | EmailDirection == "Inbound"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
| LemonDuck-email-subjects | Subject in "COVID-19 nCov Special info WHO,HALTH ADVISORY:CORONA VIRUS,The Truth of COVID-19,This is your order?,WTF,What the fcuk,broken file,farewell letter,good bye" |
| Listing Email Remediation Actions via Explorer | LatestDeliveryAction in "Hard delete,Moved to deleted items,Moved to junk folder,Soft delete" |
| Listing Email Remediation Actions via Explorer | LatestDeliveryAction in "Hard delete,Moved to deleted items,Moved to junk folder,Soft delete" |
| Local time to UTC time conversion | DeliveryAction == "Delivered"LatestDeliveryLocation == "Quarantine" |
| Local time to UTC time conversion | DeliveryAction == "Delivered"LatestDeliveryLocation == "Quarantine" |
| MDO Threat Protection Detections trend over time | |
| MDO daily detection summary report | |
| MDO daily detection summary report | |
| MDO_CountOfRecipientsEmailaddressbySubject | |
| MDO_CountOfRecipientsEmailaddressbySubject | |
| MDO_CountOfSendersEmailaddressbySubject | |
| MDO_CountOfSendersEmailaddressbySubject | |
| MDO_Countofrecipientsemailaddressesbysubject | |
| MDO_Countofrecipientsemailaddressesbysubject | |
| MDO_SummaryOfSenders | DeliveryLocation in "Inbox/folder,Junk folder,Quarantine" |
| MDO_SummaryOfSenders | DeliveryLocation in "Inbox/folder,Junk folder,Quarantine" |
| Mail reply to new domain | DeliveryLocation != "Quarantine"EmailDirection == "Inbound"OrgLevelAction != "Block"UserLevelAction != "Block" |
| Mail reply to new domain | DeliveryLocation != "Quarantine"EmailDirection == "Inbound"OrgLevelAction != "Block"UserLevelAction != "Block" |
| Mailflow by directionality | |
| Mailflow by directionality | |
| Malicious Email Campaigns by Recipient URL Clicks | EmailDirection == "Inbound"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
| Malicious Emails with QR code Urls | |
| Malicious Emails with QR code Urls | |
| Malicious email senders | LatestDeliveryLocation == "Inbox/folder" |
| Malicious email senders | LatestDeliveryLocation == "Inbox/folder" |
| Malicious emails detected per day | |
| Malicious emails detected per day | |
| Malicious mails by sender IPs | ThreatTypes has "Malware"ThreatTypes has "Phish" |
| Malicious mails by sender IPs | ThreatTypes has "Malware"ThreatTypes has "Phish" |
| Malware Detection IP and Geo Position | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Malware Detections Trend | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Malware Detections by Detection technology | DetectionMethods has "Malware"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Malware Detections by Detection technology Trend | DetectionMethods has "Malware"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Malware Detections by Sender Country | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Malware Detections by Threat Classification | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Malware Detections by delivery location | DeliveryLocation in "Failed,Quarantine"DetectionMethods has "Malware"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Malware URL Detections Trend | DetectionMethods has "Malware"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Message from an Accepted Domain with DMARC TempError | EmailDirection == "Inbound" |
| New External Sender Domains Carrying Threats | EmailDirection == "Inbound" |
| Personalized campaigns based on the first few keywords | DeliveryAction == "Delivered"EmailDirection == "Inbound" |
| Personalized campaigns based on the first few keywords | DeliveryAction == "Delivered"EmailDirection == "Inbound" |
| Personalized campaigns based on the last few keywords | DeliveryAction == "Delivered"EmailDirection == "Inbound" |
| Personalized campaigns based on the last few keywords | DeliveryAction == "Delivered"EmailDirection == "Inbound" |
| Phish Detection IP and Geo Position | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Phish Detections (High) by delivery location | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Phish Detections (Normal) by delivery location | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Phish Detections Trend | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Phish Detections by Detection technology | DetectionMethods has "Phish"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Phish Detections by Detection technology Trend | DetectionMethods has "Phish"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Phish Detections by Sender Country | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Phish Detections by Threat Classification | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Phish Detections by delivery location trend | DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"DetectionMethods has "Phish"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Phish and Malware received by user vs total amount of email | |
| Phishing Detected by LLM Content Analysis | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Phishing URL Detections Trend | DetectionMethods has "Phish"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Punycode lookalikes | |
| Punycode lookalikes | |
| QR Code URL Detections Trend | DetectionMethods has "Url"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Quarantine Malware Reason | DeliveryLocation == "Quarantine"DetectionMethods has "Malware"EmailDirection == "Inbound" |
| Quarantine Phish Reason | DeliveryLocation == "Quarantine"DetectionMethods has "Phish"EmailDirection == "Inbound" |
| Quarantine Phish Reason trend | DeliveryLocation == "Quarantine"DetectionMethods has "Phish"EmailDirection == "Inbound" |
| Quarantine Release Email Details | |
| Quarantine Release Email Details | |
| Quarantine Release Percentage | |
| Quarantine Spam Reason | DeliveryLocation == "Quarantine"DetectionMethods has "Spam"EmailDirection == "Inbound" |
| Quarantine Spam Reason trend | DeliveryLocation == "Quarantine"DetectionMethods has "Spam"EmailDirection == "Inbound" |
| Quarantine releases by Detection Types | |
| SPF Failure Trend | |
| Safe Attachments detections | |
| Safe Attachments detections | |
| SafeLinks URL detections | |
| SafeLinks URL detections | |
| SecOps Mailbox Override Count | OrgLevelAction == "Allow"OrgLevelPolicy == "SecOps Mailbox" |
| SecOps Mailbox Overrides by Threat Type | OrgLevelAction == "Allow"OrgLevelPolicy == "SecOps Mailbox" |
| Sender recipient contact establishment | DeliveryAction == "Delivered"EmailDirection == "Inbound"OrgLevelAction != "Block"SenderDisplayName contains "Microsoft"UserLevelAction != "Block" |
| Sender recipient contact establishment | DeliveryAction == "Delivered"EmailDirection == "Inbound"OrgLevelAction != "Block"SenderDisplayName contains "Microsoft"UserLevelAction != "Block" |
| Spam Detections (High) by delivery location | ConfidenceLevel has_any "Spam"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Spam Detections (Normal) by delivery location | ConfidenceLevel has_any "Spam"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Spam Detections by Detection technology | DetectionMethods has "Spam"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Spam Detections by Sender Country | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Spam and Phish allowed to inbox by Admin Overrides | |
| Spam and Phish allowed to inbox by User Overrides | |
| Spam detection by IP and its location | |
| Spam detection by delivery location | DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"DetectionMethods has "Spam"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Spam detection technologies | DetectionMethods has "Spam"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Spam detection trend | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
| Spoof Detections Trend | DetectionMethods has "Spoof" |
| Spoof Detections by Detection Technology | DetectionMethods has "Spoof" |
| Spoof Detections by Detection Technology Trend | |
| Spoof and impersonation detections by sender IP | DetectionMethods contains "impersonation"DetectionMethods contains "spoof" |
| Spoof and impersonation detections by sender IP | DetectionMethods contains "impersonation"DetectionMethods contains "spoof" |
| Spoof and impersonation phish detections | DetectionMethods contains "impersonation"DetectionMethods contains "spoof" |
| Spoof and impersonation phish detections | DetectionMethods contains "impersonation"DetectionMethods contains "spoof" |
| Spoof attempts with auth failure | DetectionMethods contains "spoof" |
| Spoof attempts with auth failure | DetectionMethods contains "spoof" |
| Suspicious Google Doc Links | |
| Suspicious Microsoft Teams Callers by Impersonation-Style Identity | |
| SuspiciousUrlClicked | SenderFromDomain != "corporatedomain.com" |
| Threat actor Phosphorus masquerading as conference organizers | |
| Threat actor Phosphorus masquerading as conference organizers (1) | DeliveryAction == "Delivered" |
| Threat actor Phosphorus masquerading as conference organizers (2) | DeliveryAction == "Delivered" |
| Top 10 Domains sending Malicious Emails (Malware+Phish+Spam) | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"SenderFromDomain !contains ".yourdomain.com"ThreatTypes has_any "Malware" |
| Top 10 Domains sending Malicious Emails (Malware+Phish+Spam) | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"SenderFromDomain !contains ".yourdomain.com"ThreatTypes has_any "Malware" |
| Top 10 External Senders (Malware) | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Malware" |
| Top 10 External Senders (Malware) | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Malware" |
| Top 10 External Senders (Phish) | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Phish" |
| Top 10 External Senders (Phish) | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Phish" |
| Top 10 External Senders (Spam) | EmailDirection == "Inbound"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Spam" |
| Top 10 External Senders (Spam) | EmailDirection == "Inbound"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Spam" |
| Top 10 External Senders (Spam) | EmailDirection == "Inbound"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Spam" |
| Top 10 Targeted Users (Malware+Phish+Spam) | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has_any "Malware" |
| Top 10 Targeted Users (Malware+Phish+Spam) | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has_any "Malware" |
| Top 10 URL domains attacking organization | |
| Top 10 URL domains attacking organization | |
| Top 10 domains sending Bulk email | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Top 10 sender domains - Admin email submissions (FN) | |
| Top 10% of most attacked users | |
| Top 10% of most attacked users | |
| Top 100 malicious email senders | ThreatTypes has "Malware"ThreatTypes has "Phish" |
| Top 100 malicious email senders | ThreatTypes has "Malware"ThreatTypes has "Phish" |
| Top 100 senders | |
| Top 100 senders | |
| Top Attacked Users by Malware Threat Classification | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Top Attacked Users by Phish Threat Classification | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Top Domains Outbound with Emails with Threats Inbound (Partner BEC) | EmailDirection in "Inbound,Outbound" |
| Top External Domains Receiving Auto-forwarded Email (Mailbox Rule and SMTP) | EmailDirection == "Outbound" |
| Top External Recipients Receiving Auto-forwarded Email (Mailbox Rule and SMTP) | EmailDirection == "Outbound" |
| Top Internal Users Auto-forwarding Email Externally (Mailbox Rule and SMTP) | EmailDirection == "Outbound" |
| Top Malware Families | OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Top Recipients Receiving Threats Delivered by Override | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Top Recipients Targeted by Impersonation or BEC | DeliveryLocation has "Inbox"DetectionMethods has "Impersonation"EmailDirection == "Inbound"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
| Top Sender Domains Delivering Threats via Override | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Top Spoof DMARC detections by Sender domain (P1/P2) | EmailDirection == "Inbound" |
| Top Spoof external domain detections by Sender domain (P1/P2) | EmailDirection == "Inbound" |
| Top Spoof intra-org detections by Sender domain (P1/P2) | EmailDirection == "Inbound" |
| Top Users receiving Malware | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
| Top Users receiving Phish | EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
| Top external malicious senders | EmailDirection == "Inbound" |
| Top external malicious senders | EmailDirection == "Inbound" |
| Top outbound recipient domains sending inbound emails with threats | EmailDirection in "Inbound,Outbound" |
| Top policies performing admin overrides | OrgLevelAction == "Allow" |
| Top policies performing admin overrides | OrgLevelAction == "Allow" |
| Top policies performing user overrides | UserLevelAction == "Allow" |
| Top policies performing user overrides | UserLevelAction == "Allow" |
| Top targeted users | ThreatTypes has "Malware"ThreatTypes has "Phish" |
| Top targeted users | ThreatTypes has "Malware"ThreatTypes has "Phish" |
| Total Emails with Admin Overrides (Allow) | OrgLevelAction == "Allow" |
| Total Emails with Admin Overrides (Block) | OrgLevelAction == "Block" |
| Total Emails with User Overrides (Allow) | UserLevelAction == "Allow" |
| Total Emails with User Overrides (Block) | UserLevelAction == "Block" |
| Total number of detections by MDO | |
| User Email Submissions (FN) - Top Inbound P2 Senders | EmailDirection == "Inbound" |
| User Email Submissions (FN) - Top Inbound P2 Senders domains | EmailDirection == "Inbound" |
| User Email Submissions (FP) - Top Inbound P2 Senders | ActionType == "UserSubmission"EmailDirection == "Inbound" |
| User Email Submissions (FP) - Top Inbound Subjects | ActionType == "UserSubmission"EmailDirection == "Inbound" |
| User Email Submissions (FP) - Top Intra-Org P2 Senders | ActionType == "UserSubmission"EmailDirection == "Intra-org" |
| User Submissions by Detection Method - Phish (FP) | ActionType == "UserSubmission"DetectionMethods has "Phish"EmailDirection == "Inbound" |
| User Submissions by Detection Method - Spam (FP) | ActionType == "UserSubmission"DetectionMethods has "Spam"EmailDirection == "Inbound" |
| User clicks on malicious inbound emails | ActionType == "ClickAllowed"EmailDirection == "Inbound"ThreatTypes has_any "Malware" |
| User clicks on malicious inbound emails | ActionType == "ClickAllowed"EmailDirection == "Inbound"ThreatTypes has_any "Malware" |
| Zero day threats | DetectionMethods has "File Detonation"DetectionMethods has "URL Detonation" |
| Zero day threats | DetectionMethods has "File Detonation"DetectionMethods has "URL Detonation" |
| Zero-day Malware Detections Trend | DetectionMethods has "Malware"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| Zero-day Phish Detections Trend | DetectionMethods has "Phish"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
| detect-archive-exfiltration-to-competitor | |
| insider-threat-detection-queries (10) | |
| jar-attachments | |
| logon-attempts-after-malicious-email | |
| powershell-activity-after-email-from-malicious-sender | |
| referral-phish-emails | |
| referral-phish-emails | |
| snip3-aviation-targeting-emails | EmailDirection == "Inbound"SenderIPv4 == "192.145.239.18" |
In solution MaturityModelForEventLogManagementM2131: DeliveryAction == "Junked"DetectionMethods contains "spam"
| Workbook |
|---|
| MaturityModelForEventLogManagement_M2131 |
In solution Microsoft Defender XDR: OrgLevelAction in "Allow,Block"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"UserLevelAction in "Allow,Block"
| Workbook |
|---|
| MicrosoftDefenderForOffice365detectionsandinsights |
In solution Microsoft Defender for Office 365:
| Workbook | Selection Criteria |
|---|---|
| MicrosoftDefenderForOffice365 |
In solution MicrosoftPurviewInsiderRiskManagement: ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user"
| Workbook |
|---|
| InsiderRiskManagement |
In solution NISTSP80053:
| Workbook | Selection Criteria |
|---|---|
| NISTSP80053 |
In solution ZeroTrust(TIC3.0):
| Workbook | Selection Criteria |
|---|---|
| ZeroTrustTIC3 |
GitHub Only:
| Workbook | Selection Criteria |
|---|---|
| MicrosoftDefenderForOffice365 | |
| MicrosoftSecurityLicenseUtilization | |
| MicrosoftSentinelDeploymentandMigrationTracker | |
| PhishingAnalysis |
References by type: 0 connectors, 260 content items, 0 ASIM parsers, 0 other parsers.
| Selection Criteria | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
EmailDirection == "Inbound" |
- | 28 | - | - | 28 |
DeliveryAction == "Delivered"EmailDirection == "Inbound" |
- | 11 | - | - | 11 |
OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
- | 10 | - | - | 10 |
OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
- | 10 | - | - | 10 |
EmailDirection == "Outbound" |
- | 9 | - | - | 9 |
DetectionMethods has "Malware"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
- | 8 | - | - | 8 |
EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
- | 8 | - | - | 8 |
DetectionMethods has "Phish"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
- | 8 | - | - | 8 |
EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
- | 8 | - | - | 8 |
EmailDirection == "Inbound"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
- | 6 | - | - | 6 |
ThreatTypes has "Malware"ThreatTypes has "Phish" |
- | 6 | - | - | 6 |
EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Malware" |
- | 6 | - | - | 6 |
EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Phish" |
- | 6 | - | - | 6 |
EmailDirection == "Inbound"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Spam" |
- | 4 | - | - | 4 |
DeliveryAction == "Delivered" |
- | 4 | - | - | 4 |
DeliveryLocation != "Quarantine"EmailDirection == "Inbound"OrgLevelAction != "Block"UserLevelAction != "Block" |
- | 4 | - | - | 4 |
EmailDirection in "Inbound,Outbound" |
- | 4 | - | - | 4 |
DeliveryAction == "Delivered"EmailDirection == "Inbound"OrgLevelAction != "Block"SenderDisplayName contains "Microsoft"UserLevelAction != "Block" |
- | 4 | - | - | 4 |
ConfidenceLevel has_any "Spam"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
- | 4 | - | - | 4 |
OrgLevelAction == "Allow"OrgLevelPolicy == "SecOps Mailbox" |
- | 4 | - | - | 4 |
OrgLevelAction == "Allow" |
- | 4 | - | - | 4 |
UserLevelAction == "Allow" |
- | 4 | - | - | 4 |
OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
- | 4 | - | - | 4 |
DeliveryLocation == "Quarantine"DetectionMethods has "Phish"EmailDirection == "Inbound" |
- | 4 | - | - | 4 |
DeliveryLocation == "Quarantine"DetectionMethods has "Spam"EmailDirection == "Inbound" |
- | 4 | - | - | 4 |
DetectionMethods has "Spam"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
- | 4 | - | - | 4 |
OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has "Spam" |
- | 4 | - | - | 4 |
DetectionMethods has "Impersonation" |
- | 4 | - | - | 4 |
DetectionMethods contains "impersonation"DetectionMethods contains "spoof" |
- | 4 | - | - | 4 |
DetectionMethods has "Spoof" |
- | 4 | - | - | 4 |
ActionType == "UserSubmission"EmailDirection == "Inbound" |
- | 4 | - | - | 4 |
DeliveryAction !has "Blocked" |
- | 2 | - | - | 2 |
DetectionMethods contains "spoof" |
- | 2 | - | - | 2 |
DeliveryAction == "Delivered"LatestDeliveryLocation == "Quarantine" |
- | 2 | - | - | 2 |
LatestDeliveryLocation == "Inbox/folder" |
- | 2 | - | - | 2 |
EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"SenderFromDomain !contains ".yourdomain.com"ThreatTypes has_any "Malware" |
- | 2 | - | - | 2 |
EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Malware" |
- | 2 | - | - | 2 |
EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"SenderFromAddress !contains ".yourdomain.com"ThreatTypes has "Phish" |
- | 2 | - | - | 2 |
EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"ThreatTypes has_any "Malware" |
- | 2 | - | - | 2 |
DeliveryLocation in "Inbox/folder,Junk folder,Quarantine" |
- | 2 | - | - | 2 |
DetectionMethods has "File Detonation"DetectionMethods has "URL Detonation" |
- | 2 | - | - | 2 |
EmailDirection in "Intra-org,Outbound"SenderFromAddress !startswith "microsoftexchange"SenderFromAddress !startswith "postmaster@"ThreatTypes == "Malware" |
- | 2 | - | - | 2 |
DeliveryLocation in "Failed,Quarantine"DetectionMethods has "Malware"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
- | 2 | - | - | 2 |
OrgLevelAction == "Block" |
- | 2 | - | - | 2 |
UserLevelAction == "Block" |
- | 2 | - | - | 2 |
DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"DetectionMethods has "Phish"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
- | 2 | - | - | 2 |
DeliveryLocation == "Quarantine"DetectionMethods has "Malware"EmailDirection == "Inbound" |
- | 2 | - | - | 2 |
ActionType == "Automated Remediation" |
- | 2 | - | - | 2 |
LatestDeliveryAction in "Hard delete,Moved to deleted items,Moved to junk folder,Soft delete" |
- | 2 | - | - | 2 |
DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"DetectionMethods has "Spam"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
- | 2 | - | - | 2 |
DetectionMethods has "Impersonation"DetectionMethods has "Spoof"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
- | 2 | - | - | 2 |
DeliveryLocation has "Inbox"DetectionMethods has "Impersonation"EmailDirection == "Inbound"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox" |
- | 2 | - | - | 2 |
ActionType == "UserSubmission"EmailDirection == "Intra-org" |
- | 2 | - | - | 2 |
ActionType == "UserSubmission"DetectionMethods has "Phish"EmailDirection == "Inbound" |
- | 2 | - | - | 2 |
ActionType == "UserSubmission"DetectionMethods has "Spam"EmailDirection == "Inbound" |
- | 2 | - | - | 2 |
DetectionMethods has "Url"EmailDirection == "Inbound"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox" |
- | 2 | - | - | 2 |
ActionType == "ClickAllowed"EmailDirection == "Inbound"ThreatTypes has_any "Malware" |
- | 2 | - | - | 2 |
DetectionMethods has "spoof" |
- | 1 | - | - | 1 |
DeliveryAction == "Delivered"ThreatTypes has "Malware"ThreatTypes has "Phish" |
- | 1 | - | - | 1 |
DeliveryLocation in "Inbox/folder,Junk folder" |
- | 1 | - | - | 1 |
EmailDirection == "Inbound"SenderIPv4 == "192.145.239.18" |
- | 1 | - | - | 1 |
SenderFromDomain != "corporatedomain.com" |
- | 1 | - | - | 1 |
EmailDirection == "Inbound"Subject startswith "RE:" |
- | 1 | - | - | 1 |
AttachmentCount == "1"EmailDirection == "Inbound" |
- | 1 | - | - | 1 |
DeliveryAction != "Blocked"EmailDirection == "Inbound"SenderIPv4 startswith "27.121.5."SenderMailFromAddress == "<>" |
- | 1 | - | - | 1 |
Subject in "COVID-19 nCov Special info WHO,HALTH ADVISORY:CORONA VIRUS,The Truth of COVID-19,This is your order?,WTF,What the fcuk,broken file,farewell letter,good bye" |
- | 1 | - | - | 1 |
DeliveryAction == "Junked"DetectionMethods contains "spam" |
- | 1 | - | - | 1 |
OrgLevelAction in "Allow,Block"OrgLevelPolicy != "Phishing simulation"OrgLevelPolicy != "SecOps Mailbox"OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"UserLevelAction in "Allow,Block" |
- | 1 | - | - | 1 |
ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user" |
- | 1 | - | - | 1 |
| Total | 0 | 260 | 0 | 0 | 260 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
UserSubmission |
- | 10 | - | - | 10 |
Automated Remediation |
- | 2 | - | - | 2 |
ClickAllowed |
- | 2 | - | - | 2 |
Add member to role |
- | 1 | - | - | 1 |
Add user |
- | 1 | - | - | 1 |
InteractiveLogon |
- | 1 | - | - | 1 |
RemoteInteractiveLogon |
- | 1 | - | - | 1 |
Reset user password |
- | 1 | - | - | 1 |
ResourceAccess |
- | 1 | - | - | 1 |
Sign-in |
- | 1 | - | - | 1 |
Update user |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
1 |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has_any Spam |
- | 4 | - | - | 4 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Delivered |
- | 22 | - | - | 22 |
!has Blocked |
- | 2 | - | - | 2 |
!= Blocked |
- | 1 | - | - | 1 |
Junked |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Quarantine |
- | 18 | - | - | 18 |
Inbox/folder |
- | 7 | - | - | 7 |
Junk folder |
- | 7 | - | - | 7 |
Failed |
- | 6 | - | - | 6 |
!= Quarantine |
- | 4 | - | - | 4 |
Dropped |
- | 4 | - | - | 4 |
has Inbox |
- | 2 | - | - | 2 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has Phish |
- | 16 | - | - | 16 |
has Malware |
- | 12 | - | - | 12 |
has Spam |
- | 12 | - | - | 12 |
has Impersonation |
- | 8 | - | - | 8 |
contains spoof |
- | 6 | - | - | 6 |
has Spoof |
- | 6 | - | - | 6 |
contains impersonation |
- | 4 | - | - | 4 |
has File Detonation |
- | 2 | - | - | 2 |
has URL Detonation |
- | 2 | - | - | 2 |
has Url |
- | 2 | - | - | 2 |
has spoof |
- | 1 | - | - | 1 |
contains spam |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Inbound |
- | 131 | - | - | 131 |
Outbound |
- | 15 | - | - | 15 |
Intra-org |
- | 4 | - | - | 4 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Hard delete |
- | 2 | - | - | 2 |
Moved to deleted items |
- | 2 | - | - | 2 |
Moved to junk folder |
- | 2 | - | - | 2 |
Soft delete |
- | 2 | - | - | 2 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Quarantine |
- | 2 | - | - | 2 |
Inbox/folder |
- | 2 | - | - | 2 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Allow |
- | 9 | - | - | 9 |
!= Block |
- | 8 | - | - | 8 |
Block |
- | 3 | - | - | 3 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
!= Phishing simulation |
- | 108 | - | - | 108 |
!= SecOps Mailbox |
- | 108 | - | - | 108 |
SecOps Mailbox |
- | 4 | - | - | 4 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
contains Microsoft |
- | 4 | - | - | 4 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
!contains .yourdomain.com |
- | 8 | - | - | 8 |
!startswith microsoftexchange |
- | 2 | - | - | 2 |
!startswith postmaster@ |
- | 2 | - | - | 2 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
!contains .yourdomain.com |
- | 2 | - | - | 2 |
!= corporatedomain.com |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
192.145.239.18 |
- | 1 | - | - | 1 |
startswith 27.121.5. |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
<> |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
startswith RE: |
- | 1 | - | - | 1 |
COVID-19 nCov Special info WHO |
- | 1 | - | - | 1 |
HALTH ADVISORY:CORONA VIRUS |
- | 1 | - | - | 1 |
The Truth of COVID-19 |
- | 1 | - | - | 1 |
This is your order? |
- | 1 | - | - | 1 |
WTF |
- | 1 | - | - | 1 |
What the fcuk |
- | 1 | - | - | 1 |
broken file |
- | 1 | - | - | 1 |
farewell letter |
- | 1 | - | - | 1 |
good bye |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has Malware |
- | 25 | - | - | 25 |
has Phish |
- | 25 | - | - | 25 |
has Spam |
- | 16 | - | - | 16 |
has_any Malware |
- | 6 | - | - | 6 |
Malware |
- | 2 | - | - | 2 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
!= Block |
- | 8 | - | - | 8 |
Allow |
- | 5 | - | - | 5 |
Block |
- | 3 | - | - | 3 |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊