EmailEvents

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Microsoft 365 email events, including email delivery and blocking events

Attribute Value
Category Defender
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Lake-Only Ingestion ✓ Yes (source)
Azure Monitor Tables Reference View Documentation
Defender XDR Advanced Hunting Schema View Documentation

Contents

Schema (55 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account
AdditionalFields dynamic Additional information about the entity or event.
AttachmentCount int Number of attachments in the email.
AuthenticationDetails string List of pass or fail verdicts by email authentication protocols like DMARC, DKIM, SPF or a combination of multiple authentication types (CompAuth).
BulkComplaintLevel int Threshold assigned to email from bulk mailers, a high bulk complaint level (BCL) means the email is more likely to generate complaints, and thus more likely to be spam.
Cc dynamic Indicates the addresses which are listed in Cc fields of an email
ConfidenceLevel string List of confidence levels of any spam or phishing verdicts. For spam, this column shows the spam confidence level (SCL), indicating if the email was skipped (-1), found to be not spam (0,1), found to be spam with moderate confidence (5,6), or found to be spam with high confidence (9). For phishing, this column displays whether the confidence level is "High" or "Low".
Connectors string Custom instructions that define organizational mail flow and how the email was routed.
Context string Configuration context data of the machine
DeliveryAction string Action of the delivered email.
DeliveryLocation string Location of the delivered email: Inbox/Folder, On-premises/External, Junk, Quarantine, Failed, Dropped, Deleted items.
DetectionMethods string Delivery action of the email: Delivered, Junked, Blocked, or Replaced.
DistributionList string Name of distribution list that the recipient was a member of and to which the email was sent, if applicable; shows top-level distribution list if nested lists are involved
EmailAction string Final action taken on the email based on filter verdict, policies, and user actions: Move message to junk mail folder, Add X-header, Modify subject, Redirect message, Delete message, send to quarantine, No action taken, Bcc message.
EmailActionPolicy string Action policy that took effect: Antispam high-confidence, Antispam, Antispam bulk mail, Antispam phishing, Anti-phishing domain impersonation, Anti-phishing user impersonation, Anti-phishing spoof, Anti-phishing graph impersonation, Antimalware Safe Attachments, Enterprise Transport Rules (ETR).
EmailActionPolicyGuid string Unique identifier of the policy that took effect.
EmailClusterId long Identifier of the email cluster. Emails are clustered (grouped) based on heuristic analysis of their contents.
EmailDirection string Email direction: Inbound, Outbound, Intra-org.
EmailLanguage string Detected language of the email content.
EmailSize int Size of the email message.
ExchangeTransportRule string Mail flow rules (also known as transport rules) are similar to Inbox rules that are available in Outlook and Outlook on the web. The main difference is mail flow rules take action on messages while they're in transit.
ForwardingInformation string A JSON array of forwarding details including the forwarding user and the forwarding type
InternetMessageId string Public-facing identifier for the email that is set by the sending email system.
IsFirstContact bool Is this the first contact between sender and reciever.
LastEventExecutionTime datetime Date and time (UTC) when the record was updated post merge.
LatestDeliveryAction string Last known action attempted on an email by the service or by an admin through manual remediation.
LatestDeliveryLocation string Last known location of the email.
NetworkMessageId string Unique identifier for the email, generated by Office 365.
OrgLevelAction string Action taken on the email in response to matches to a policy defined at the organizational level.
OrgLevelPolicy string Organizational policy that triggered the action taken on the email.
RecipientDomain string Domain of the recipient of the email.
RecipientEmailAddress string Recipient email address or email address of the recipient after distribution list expansion.
RecipientObjectId string Email recipient Azure AD identifier.
ReportId string Unique identifier for the event.
SenderDisplayName string Sender email address in the from header, which is visible to email recipients on their email clients.
SenderFromAddress string Sender domain in the from header, which is visible to email recipients on their email clients.
SenderFromDomain string Verdict from the email filtering stack on whether the email contains malware, phishing, or other threats.
SenderIPv4 string IPv4 address of the last detected mail server that relayed the message.
SenderIPv6 string IPv6 address of the last detected mail server that relayed the message.
SenderMailFromAddress string Sender email address in the MAIL from header, also known as the envelope sender or the Return-Path address.
SenderMailFromDomain string Sender domain in the MAIL from header, also known as the envelope sender or the Return-Path address.
SenderObjectId string Sender email address in the from header, which is visible to email recipients on their email clients.
SourceSystem string The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics
Subject string Email subject field.
TenantId string The Log Analytics workspace ID
ThreatClassification string Indicates the threat classification of the mail
ThreatNames string Sender email address in the from header, which is visible to email recipients on their email clients.
ThreatTypes string Verdict from the email filtering stack on whether the email contains malware, phishing, or other threats.
TimeGenerated datetime Date and time (UTC) when the record was generated.
To dynamic Indicates the addresses which are listed in To fields of an email
Type string The name of the table
UrlCount int Number of embedded URLs in the email.
UserLevelAction string Action taken on the email in response to matches to a mailbox policy defined by the recipient.
UserLevelPolicy string End user mailbox policy that triggered the action taken on the email.

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (11)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Microsoft Defender XDR

Content Items Using This Table (367)

Analytic Rules (10)

In solution Microsoft Business Applications: EmailDirection == "Outbound"

Analytic Rule
Dataverse - Terminated employee exfiltration over email

In solution Threat Intelligence:

Analytic Rule Selection Criteria
TI Map URL Entity to EmailUrlInfo
TI map Domain entity to EmailEvents
TI map Domain entity to EmailUrlInfo DeliveryAction !has "Blocked"
TI map Email entity to EmailEvents

In solution Threat Intelligence (NEW):

Analytic Rule Selection Criteria
TI Map Domain entity to EmailEvents
TI Map Domain entity to EmailUrlInfo DeliveryAction !has "Blocked"
TI Map Email entity to EmailEvents
TI Map URL Entity to EmailUrlInfo

Standalone Content:

Analytic Rule Selection Criteria
Star Blizzard C2 Domains August 2022

Hunting Queries (347)

In solution Business Email Compromise - Financial Fraud:

Hunting Query Selection Criteria
Email Forwarding Configuration with SAP download

In solution Microsoft Defender XDR:

Hunting Query Selection Criteria
Automated Remediation Delivery to Action Latency ActionType == "Automated Remediation"
Automated email notifications and suspicious sign-in activity
Automatic External Email Forwarding Overview by Type (Mailbox Rule and SMTP) EmailDirection == "Outbound"
Bad email percentage of Inbound emails EmailDirection == "Inbound"
Bulk Emails by Sender Bulk Complaint level EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Calculate overall MDO efficacy
CompAuth Failure Trend
DKIM Failure Trend
DMARC Failure Trend
Determine Successfully Delivered Phishing Emails by top IP Addresses DeliveryAction == "Delivered"
ThreatTypes has "Malware"
ThreatTypes has "Phish"
Determine Successfully Delivered Phishing Emails to Inbox/Junk folder. DeliveryLocation in "Inbox/folder,Junk folder"
Email Top 10 Domains sending Spam EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Email Top 10 Targeted Users (Spam) EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Email Top 15 Domains sending Spam with Additional Details EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Email Top 15 Targeted Users (Spam) with Additional Details EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Email Top Domains sending Malware EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Email Top Domains sending Phish EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Email bombing attacks DeliveryAction == "Delivered"
Files share contents and suspicious sign-in activity
First-Contact External Email Senders EmailDirection == "Inbound"
Hunt for email bombing attacks EmailDirection == "Inbound"
Impersonation Detections Trend DetectionMethods has "Impersonation"
Impersonation Detections by Detection Technology DetectionMethods has "Impersonation"
Impersonation Detections by Detection Technology Trend
Impersonation and Spoof Detections by Sender Country DetectionMethods has "Impersonation"
DetectionMethods has "Spoof"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
Inbound Sender Domains Failing Email Authentication EmailDirection == "Inbound"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
Largest Malicious Email Campaigns by Cluster EmailDirection == "Inbound"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
MDO Threat Protection Detections trend over time
Malicious Email Campaigns by Recipient URL Clicks EmailDirection == "Inbound"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
Malware Detection IP and Geo Position OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Malware Detections Trend OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Malware Detections by Detection technology DetectionMethods has "Malware"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Malware Detections by Detection technology Trend DetectionMethods has "Malware"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Malware Detections by Sender Country OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Malware Detections by Threat Classification OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Malware Detections by delivery location DeliveryLocation in "Failed,Quarantine"
DetectionMethods has "Malware"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Malware URL Detections Trend DetectionMethods has "Malware"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Message from an Accepted Domain with DMARC TempError EmailDirection == "Inbound"
New External Sender Domains Carrying Threats EmailDirection == "Inbound"
Phish Detection IP and Geo Position OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Phish Detections (High) by delivery location OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Phish Detections (Normal) by delivery location OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Phish Detections Trend OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Phish Detections by Detection technology DetectionMethods has "Phish"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Phish Detections by Detection technology Trend DetectionMethods has "Phish"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Phish Detections by Sender Country OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Phish Detections by Threat Classification OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Phish Detections by delivery location trend DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Phishing Detected by LLM Content Analysis OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Phishing URL Detections Trend DetectionMethods has "Phish"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
QR Code URL Detections Trend DetectionMethods has "Url"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Quarantine Malware Reason DeliveryLocation == "Quarantine"
DetectionMethods has "Malware"
EmailDirection == "Inbound"
Quarantine Phish Reason DeliveryLocation == "Quarantine"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
Quarantine Phish Reason trend DeliveryLocation == "Quarantine"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
Quarantine Release Percentage
Quarantine Spam Reason DeliveryLocation == "Quarantine"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
Quarantine Spam Reason trend DeliveryLocation == "Quarantine"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
Quarantine releases by Detection Types
SPF Failure Trend
SecOps Mailbox Override Count OrgLevelAction == "Allow"
OrgLevelPolicy == "SecOps Mailbox"
SecOps Mailbox Overrides by Threat Type OrgLevelAction == "Allow"
OrgLevelPolicy == "SecOps Mailbox"
Spam Detections (High) by delivery location ConfidenceLevel has_any "Spam"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Spam Detections (Normal) by delivery location ConfidenceLevel has_any "Spam"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Spam Detections by Detection technology DetectionMethods has "Spam"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Spam Detections by Sender Country OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Spam and Phish allowed to inbox by Admin Overrides
Spam and Phish allowed to inbox by User Overrides
Spam detection by IP and its location
Spam detection by delivery location DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Spam detection technologies DetectionMethods has "Spam"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Spam detection trend OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Spoof Detections Trend DetectionMethods has "Spoof"
Spoof Detections by Detection Technology DetectionMethods has "Spoof"
Spoof Detections by Detection Technology Trend
Spoofing attempts from Specific Domains DetectionMethods has "spoof"
Suspicious Microsoft Teams Callers by Impersonation-Style Identity
Top 10 External Senders (Spam) EmailDirection == "Inbound"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Spam"
Top 10 domains sending Bulk email EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Top 10 sender domains - Admin email submissions (FN)
Top Attacked Users by Malware Threat Classification EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Top Attacked Users by Phish Threat Classification EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Top Domains Outbound with Emails with Threats Inbound (Partner BEC) EmailDirection in "Inbound,Outbound"
Top External Domains Receiving Auto-forwarded Email (Mailbox Rule and SMTP) EmailDirection == "Outbound"
Top External Recipients Receiving Auto-forwarded Email (Mailbox Rule and SMTP) EmailDirection == "Outbound"
Top Internal Users Auto-forwarding Email Externally (Mailbox Rule and SMTP) EmailDirection == "Outbound"
Top Malware Families OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Top Recipients Receiving Threats Delivered by Override EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Top Recipients Targeted by Impersonation or BEC DeliveryLocation has "Inbox"
DetectionMethods has "Impersonation"
EmailDirection == "Inbound"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
Top Sender Domains Delivering Threats via Override EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Top Spoof DMARC detections by Sender domain (P1/P2) EmailDirection == "Inbound"
Top Spoof external domain detections by Sender domain (P1/P2) EmailDirection == "Inbound"
Top Spoof intra-org detections by Sender domain (P1/P2) EmailDirection == "Inbound"
Top Users receiving Malware EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Top Users receiving Phish EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Top outbound recipient domains sending inbound emails with threats EmailDirection in "Inbound,Outbound"
Total Emails with Admin Overrides (Allow) OrgLevelAction == "Allow"
Total Emails with Admin Overrides (Block) OrgLevelAction == "Block"
Total Emails with User Overrides (Allow) UserLevelAction == "Allow"
Total Emails with User Overrides (Block) UserLevelAction == "Block"
Total number of detections by MDO
User Email Submissions (FN) - Top Inbound P2 Senders EmailDirection == "Inbound"
User Email Submissions (FN) - Top Inbound P2 Senders domains EmailDirection == "Inbound"
User Email Submissions (FP) - Top Inbound P2 Senders ActionType == "UserSubmission"
EmailDirection == "Inbound"
User Email Submissions (FP) - Top Inbound Subjects ActionType == "UserSubmission"
EmailDirection == "Inbound"
User Email Submissions (FP) - Top Intra-Org P2 Senders ActionType == "UserSubmission"
EmailDirection == "Intra-org"
User Submissions by Detection Method - Phish (FP) ActionType == "UserSubmission"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
User Submissions by Detection Method - Spam (FP) ActionType == "UserSubmission"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
Zero-day Malware Detections Trend DetectionMethods has "Malware"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Zero-day Phish Detections Trend DetectionMethods has "Phish"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"

Standalone Content: DeliveryAction == "Delivered"
EmailDirection == "Inbound"

Hunting Query
Raw IP Address Used as URL Domain

GitHub Only:

Hunting Query Selection Criteria
Attacked more than x times average
Attacked more than x times average
Authentication failures by time and authentication type
Authentication failures by time and authentication type
Automated Remediation Delivery to Action Latency ActionType == "Automated Remediation"
Automated email notifications and suspicious sign-in activity
Automatic External Email Forwarding Overview by Type (Mailbox Rule and SMTP) EmailDirection == "Outbound"
Bad email percentage of Inbound emails EmailDirection == "Inbound"
Bazacall Emails
Bulk Emails by Sender Bulk Complaint level EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Calculate overall MDO efficacy
Campaign with suspicious keywords DeliveryAction == "Delivered"
EmailDirection == "Inbound"
Campaign with suspicious keywords DeliveryAction == "Delivered"
EmailDirection == "Inbound"
CompAuth Failure Trend
Custom detection-Emails with QR from non-prevalent senders
Custom detection-Emails with QR from non-prevalent senders
DKIM Failure Trend
DMARC Failure Trend
Detections by detection methods
Detections by detection methods
Display Name - Spoof and Impersonation DeliveryAction == "Delivered"
EmailDirection == "Inbound"
OrgLevelAction != "Block"
SenderDisplayName contains "Microsoft"
UserLevelAction != "Block"
Display Name - Spoof and Impersonation DeliveryAction == "Delivered"
EmailDirection == "Inbound"
OrgLevelAction != "Block"
SenderDisplayName contains "Microsoft"
UserLevelAction != "Block"
Email Top 10 Domains sending Spam EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Email Top 10 Targeted Users (Spam) EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Email Top 15 Domains sending Spam with Additional Details EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Email Top 15 Targeted Users (Spam) with Additional Details EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Email Top Domains sending Malware EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Email Top Domains sending Phish EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Email bombing attacks DeliveryAction == "Delivered"
Email containing malware sent by an internal sender EmailDirection in "Intra-org,Outbound"
SenderFromAddress !startswith "microsoftexchange"
SenderFromAddress !startswith "postmaster@"
ThreatTypes == "Malware"
Email containing malware sent by an internal sender EmailDirection in "Intra-org,Outbound"
SenderFromAddress !startswith "microsoftexchange"
SenderFromAddress !startswith "postmaster@"
ThreatTypes == "Malware"
Email malware detection report
Email malware detection report
Email sender IP address Geo location information
Email sender IP address Geo location information
Emails delivered having URLs from QR codes DeliveryAction == "Delivered"
EmailDirection == "Inbound"
Emails delivered having URLs from QR codes DeliveryAction == "Delivered"
EmailDirection == "Inbound"
Emails with QR codes and suspicious keywords in subject DeliveryAction == "Delivered"
EmailDirection == "Inbound"
Emails with QR codes and suspicious keywords in subject DeliveryAction == "Delivered"
EmailDirection == "Inbound"
Emails with QR codes from non-prevalent sender
Emails with QR codes from non-prevalent sender
Empty Sender Phish Delivered to Inbox DeliveryAction != "Blocked"
EmailDirection == "Inbound"
SenderIPv4 startswith "27.121.5."
SenderMailFromAddress == "<>"
Fake Replies EmailDirection == "Inbound"
Subject startswith "RE:"
First-Contact External Email Senders EmailDirection == "Inbound"
Good emails from senders with bad patterns EmailDirection == "Inbound"
Good emails from senders with bad patterns EmailDirection == "Inbound"
High Confidence Phish Released
High Confidence Phish Released
Hunt for email bombing attacks EmailDirection == "Inbound"
Hunt for email conversation take over attempts DeliveryLocation != "Quarantine"
EmailDirection == "Inbound"
OrgLevelAction != "Block"
UserLevelAction != "Block"
Hunt for email conversation take over attempts DeliveryLocation != "Quarantine"
EmailDirection == "Inbound"
OrgLevelAction != "Block"
UserLevelAction != "Block"
Hunting for sender patterns
Hunting for sender patterns
Hunting for user signals-clusters EmailDirection == "Inbound"
Hunting for user signals-clusters EmailDirection == "Inbound"
IcedId attachments AttachmentCount == "1"
EmailDirection == "Inbound"
Impersonation Detections Trend DetectionMethods has "Impersonation"
Impersonation Detections by Detection Technology DetectionMethods has "Impersonation"
Impersonation Detections by Detection Technology Trend
Impersonation and Spoof Detections by Sender Country DetectionMethods has "Impersonation"
DetectionMethods has "Spoof"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
Inbound Sender Domains Failing Email Authentication EmailDirection == "Inbound"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
Inbound emails with QR code URLs EmailDirection == "Inbound"
Inbound emails with QR code URLs EmailDirection == "Inbound"
Largest Malicious Email Campaigns by Cluster EmailDirection == "Inbound"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
LemonDuck-email-subjects Subject in "COVID-19 nCov Special info WHO,HALTH ADVISORY:CORONA VIRUS,The Truth of COVID-19,This is your order?,WTF,What the fcuk,broken file,farewell letter,good bye"
Listing Email Remediation Actions via Explorer LatestDeliveryAction in "Hard delete,Moved to deleted items,Moved to junk folder,Soft delete"
Listing Email Remediation Actions via Explorer LatestDeliveryAction in "Hard delete,Moved to deleted items,Moved to junk folder,Soft delete"
Local time to UTC time conversion DeliveryAction == "Delivered"
LatestDeliveryLocation == "Quarantine"
Local time to UTC time conversion DeliveryAction == "Delivered"
LatestDeliveryLocation == "Quarantine"
MDO Threat Protection Detections trend over time
MDO daily detection summary report
MDO daily detection summary report
MDO_CountOfRecipientsEmailaddressbySubject
MDO_CountOfRecipientsEmailaddressbySubject
MDO_CountOfSendersEmailaddressbySubject
MDO_CountOfSendersEmailaddressbySubject
MDO_Countofrecipientsemailaddressesbysubject
MDO_Countofrecipientsemailaddressesbysubject
MDO_SummaryOfSenders DeliveryLocation in "Inbox/folder,Junk folder,Quarantine"
MDO_SummaryOfSenders DeliveryLocation in "Inbox/folder,Junk folder,Quarantine"
Mail reply to new domain DeliveryLocation != "Quarantine"
EmailDirection == "Inbound"
OrgLevelAction != "Block"
UserLevelAction != "Block"
Mail reply to new domain DeliveryLocation != "Quarantine"
EmailDirection == "Inbound"
OrgLevelAction != "Block"
UserLevelAction != "Block"
Mailflow by directionality
Mailflow by directionality
Malicious Email Campaigns by Recipient URL Clicks EmailDirection == "Inbound"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
Malicious Emails with QR code Urls
Malicious Emails with QR code Urls
Malicious email senders LatestDeliveryLocation == "Inbox/folder"
Malicious email senders LatestDeliveryLocation == "Inbox/folder"
Malicious emails detected per day
Malicious emails detected per day
Malicious mails by sender IPs ThreatTypes has "Malware"
ThreatTypes has "Phish"
Malicious mails by sender IPs ThreatTypes has "Malware"
ThreatTypes has "Phish"
Malware Detection IP and Geo Position OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Malware Detections Trend OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Malware Detections by Detection technology DetectionMethods has "Malware"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Malware Detections by Detection technology Trend DetectionMethods has "Malware"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Malware Detections by Sender Country OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Malware Detections by Threat Classification OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Malware Detections by delivery location DeliveryLocation in "Failed,Quarantine"
DetectionMethods has "Malware"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Malware URL Detections Trend DetectionMethods has "Malware"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Message from an Accepted Domain with DMARC TempError EmailDirection == "Inbound"
New External Sender Domains Carrying Threats EmailDirection == "Inbound"
Personalized campaigns based on the first few keywords DeliveryAction == "Delivered"
EmailDirection == "Inbound"
Personalized campaigns based on the first few keywords DeliveryAction == "Delivered"
EmailDirection == "Inbound"
Personalized campaigns based on the last few keywords DeliveryAction == "Delivered"
EmailDirection == "Inbound"
Personalized campaigns based on the last few keywords DeliveryAction == "Delivered"
EmailDirection == "Inbound"
Phish Detection IP and Geo Position OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Phish Detections (High) by delivery location OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Phish Detections (Normal) by delivery location OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Phish Detections Trend OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Phish Detections by Detection technology DetectionMethods has "Phish"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Phish Detections by Detection technology Trend DetectionMethods has "Phish"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Phish Detections by Sender Country OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Phish Detections by Threat Classification OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Phish Detections by delivery location trend DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Phish and Malware received by user vs total amount of email
Phishing Detected by LLM Content Analysis OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Phishing URL Detections Trend DetectionMethods has "Phish"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Punycode lookalikes
Punycode lookalikes
QR Code URL Detections Trend DetectionMethods has "Url"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Quarantine Malware Reason DeliveryLocation == "Quarantine"
DetectionMethods has "Malware"
EmailDirection == "Inbound"
Quarantine Phish Reason DeliveryLocation == "Quarantine"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
Quarantine Phish Reason trend DeliveryLocation == "Quarantine"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
Quarantine Release Email Details
Quarantine Release Email Details
Quarantine Release Percentage
Quarantine Spam Reason DeliveryLocation == "Quarantine"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
Quarantine Spam Reason trend DeliveryLocation == "Quarantine"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
Quarantine releases by Detection Types
SPF Failure Trend
Safe Attachments detections
Safe Attachments detections
SafeLinks URL detections
SafeLinks URL detections
SecOps Mailbox Override Count OrgLevelAction == "Allow"
OrgLevelPolicy == "SecOps Mailbox"
SecOps Mailbox Overrides by Threat Type OrgLevelAction == "Allow"
OrgLevelPolicy == "SecOps Mailbox"
Sender recipient contact establishment DeliveryAction == "Delivered"
EmailDirection == "Inbound"
OrgLevelAction != "Block"
SenderDisplayName contains "Microsoft"
UserLevelAction != "Block"
Sender recipient contact establishment DeliveryAction == "Delivered"
EmailDirection == "Inbound"
OrgLevelAction != "Block"
SenderDisplayName contains "Microsoft"
UserLevelAction != "Block"
Spam Detections (High) by delivery location ConfidenceLevel has_any "Spam"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Spam Detections (Normal) by delivery location ConfidenceLevel has_any "Spam"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Spam Detections by Detection technology DetectionMethods has "Spam"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Spam Detections by Sender Country OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Spam and Phish allowed to inbox by Admin Overrides
Spam and Phish allowed to inbox by User Overrides
Spam detection by IP and its location
Spam detection by delivery location DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Spam detection technologies DetectionMethods has "Spam"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Spam detection trend OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
Spoof Detections Trend DetectionMethods has "Spoof"
Spoof Detections by Detection Technology DetectionMethods has "Spoof"
Spoof Detections by Detection Technology Trend
Spoof and impersonation detections by sender IP DetectionMethods contains "impersonation"
DetectionMethods contains "spoof"
Spoof and impersonation detections by sender IP DetectionMethods contains "impersonation"
DetectionMethods contains "spoof"
Spoof and impersonation phish detections DetectionMethods contains "impersonation"
DetectionMethods contains "spoof"
Spoof and impersonation phish detections DetectionMethods contains "impersonation"
DetectionMethods contains "spoof"
Spoof attempts with auth failure DetectionMethods contains "spoof"
Spoof attempts with auth failure DetectionMethods contains "spoof"
Suspicious Google Doc Links
Suspicious Microsoft Teams Callers by Impersonation-Style Identity
SuspiciousUrlClicked SenderFromDomain != "corporatedomain.com"
Threat actor Phosphorus masquerading as conference organizers
Threat actor Phosphorus masquerading as conference organizers (1) DeliveryAction == "Delivered"
Threat actor Phosphorus masquerading as conference organizers (2) DeliveryAction == "Delivered"
Top 10 Domains sending Malicious Emails (Malware+Phish+Spam) EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
SenderFromDomain !contains ".yourdomain.com"
ThreatTypes has_any "Malware"
Top 10 Domains sending Malicious Emails (Malware+Phish+Spam) EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
SenderFromDomain !contains ".yourdomain.com"
ThreatTypes has_any "Malware"
Top 10 External Senders (Malware) EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Malware"
Top 10 External Senders (Malware) EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Malware"
Top 10 External Senders (Phish) EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Phish"
Top 10 External Senders (Phish) EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Phish"
Top 10 External Senders (Spam) EmailDirection == "Inbound"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Spam"
Top 10 External Senders (Spam) EmailDirection == "Inbound"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Spam"
Top 10 External Senders (Spam) EmailDirection == "Inbound"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Spam"
Top 10 Targeted Users (Malware+Phish+Spam) EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has_any "Malware"
Top 10 Targeted Users (Malware+Phish+Spam) EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has_any "Malware"
Top 10 URL domains attacking organization
Top 10 URL domains attacking organization
Top 10 domains sending Bulk email EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Top 10 sender domains - Admin email submissions (FN)
Top 10% of most attacked users
Top 10% of most attacked users
Top 100 malicious email senders ThreatTypes has "Malware"
ThreatTypes has "Phish"
Top 100 malicious email senders ThreatTypes has "Malware"
ThreatTypes has "Phish"
Top 100 senders
Top 100 senders
Top Attacked Users by Malware Threat Classification EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Top Attacked Users by Phish Threat Classification EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Top Domains Outbound with Emails with Threats Inbound (Partner BEC) EmailDirection in "Inbound,Outbound"
Top External Domains Receiving Auto-forwarded Email (Mailbox Rule and SMTP) EmailDirection == "Outbound"
Top External Recipients Receiving Auto-forwarded Email (Mailbox Rule and SMTP) EmailDirection == "Outbound"
Top Internal Users Auto-forwarding Email Externally (Mailbox Rule and SMTP) EmailDirection == "Outbound"
Top Malware Families OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Top Recipients Receiving Threats Delivered by Override EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Top Recipients Targeted by Impersonation or BEC DeliveryLocation has "Inbox"
DetectionMethods has "Impersonation"
EmailDirection == "Inbound"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
Top Sender Domains Delivering Threats via Override EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Top Spoof DMARC detections by Sender domain (P1/P2) EmailDirection == "Inbound"
Top Spoof external domain detections by Sender domain (P1/P2) EmailDirection == "Inbound"
Top Spoof intra-org detections by Sender domain (P1/P2) EmailDirection == "Inbound"
Top Users receiving Malware EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
Top Users receiving Phish EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
Top external malicious senders EmailDirection == "Inbound"
Top external malicious senders EmailDirection == "Inbound"
Top outbound recipient domains sending inbound emails with threats EmailDirection in "Inbound,Outbound"
Top policies performing admin overrides OrgLevelAction == "Allow"
Top policies performing admin overrides OrgLevelAction == "Allow"
Top policies performing user overrides UserLevelAction == "Allow"
Top policies performing user overrides UserLevelAction == "Allow"
Top targeted users ThreatTypes has "Malware"
ThreatTypes has "Phish"
Top targeted users ThreatTypes has "Malware"
ThreatTypes has "Phish"
Total Emails with Admin Overrides (Allow) OrgLevelAction == "Allow"
Total Emails with Admin Overrides (Block) OrgLevelAction == "Block"
Total Emails with User Overrides (Allow) UserLevelAction == "Allow"
Total Emails with User Overrides (Block) UserLevelAction == "Block"
Total number of detections by MDO
User Email Submissions (FN) - Top Inbound P2 Senders EmailDirection == "Inbound"
User Email Submissions (FN) - Top Inbound P2 Senders domains EmailDirection == "Inbound"
User Email Submissions (FP) - Top Inbound P2 Senders ActionType == "UserSubmission"
EmailDirection == "Inbound"
User Email Submissions (FP) - Top Inbound Subjects ActionType == "UserSubmission"
EmailDirection == "Inbound"
User Email Submissions (FP) - Top Intra-Org P2 Senders ActionType == "UserSubmission"
EmailDirection == "Intra-org"
User Submissions by Detection Method - Phish (FP) ActionType == "UserSubmission"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
User Submissions by Detection Method - Spam (FP) ActionType == "UserSubmission"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
User clicks on malicious inbound emails ActionType == "ClickAllowed"
EmailDirection == "Inbound"
ThreatTypes has_any "Malware"
User clicks on malicious inbound emails ActionType == "ClickAllowed"
EmailDirection == "Inbound"
ThreatTypes has_any "Malware"
Zero day threats DetectionMethods has "File Detonation"
DetectionMethods has "URL Detonation"
Zero day threats DetectionMethods has "File Detonation"
DetectionMethods has "URL Detonation"
Zero-day Malware Detections Trend DetectionMethods has "Malware"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
Zero-day Phish Detections Trend DetectionMethods has "Phish"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
detect-archive-exfiltration-to-competitor
insider-threat-detection-queries (10)
jar-attachments
logon-attempts-after-malicious-email
powershell-activity-after-email-from-malicious-sender
referral-phish-emails
referral-phish-emails
snip3-aviation-targeting-emails EmailDirection == "Inbound"
SenderIPv4 == "192.145.239.18"

Workbooks (10)

In solution MaturityModelForEventLogManagementM2131: DeliveryAction == "Junked"
DetectionMethods contains "spam"

Workbook
MaturityModelForEventLogManagement_M2131

In solution Microsoft Defender XDR: OrgLevelAction in "Allow,Block"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
UserLevelAction in "Allow,Block"

Workbook
MicrosoftDefenderForOffice365detectionsandinsights

In solution Microsoft Defender for Office 365:

Workbook Selection Criteria
MicrosoftDefenderForOffice365

In solution MicrosoftPurviewInsiderRiskManagement: ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user"

Workbook
InsiderRiskManagement

In solution NISTSP80053:

Workbook Selection Criteria
NISTSP80053

In solution ZeroTrust(TIC3.0):

Workbook Selection Criteria
ZeroTrustTIC3

GitHub Only:

Workbook Selection Criteria
MicrosoftDefenderForOffice365
MicrosoftSecurityLicenseUtilization
MicrosoftSentinelDeploymentandMigrationTracker
PhishingAnalysis

Selection Criteria Summary (69 criteria, 260 total references)

References by type: 0 connectors, 260 content items, 0 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
EmailDirection == "Inbound" - 28 - - 28
DeliveryAction == "Delivered"
EmailDirection == "Inbound"
- 11 - - 11
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
- 10 - - 10
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
- 10 - - 10
EmailDirection == "Outbound" - 9 - - 9
DetectionMethods has "Malware"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
- 8 - - 8
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
- 8 - - 8
DetectionMethods has "Phish"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
- 8 - - 8
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
- 8 - - 8
EmailDirection == "Inbound"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
- 6 - - 6
ThreatTypes has "Malware"
ThreatTypes has "Phish"
- 6 - - 6
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Malware"
- 6 - - 6
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Phish"
- 6 - - 6
EmailDirection == "Inbound"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Spam"
- 4 - - 4
DeliveryAction == "Delivered" - 4 - - 4
DeliveryLocation != "Quarantine"
EmailDirection == "Inbound"
OrgLevelAction != "Block"
UserLevelAction != "Block"
- 4 - - 4
EmailDirection in "Inbound,Outbound" - 4 - - 4
DeliveryAction == "Delivered"
EmailDirection == "Inbound"
OrgLevelAction != "Block"
SenderDisplayName contains "Microsoft"
UserLevelAction != "Block"
- 4 - - 4
ConfidenceLevel has_any "Spam"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
- 4 - - 4
OrgLevelAction == "Allow"
OrgLevelPolicy == "SecOps Mailbox"
- 4 - - 4
OrgLevelAction == "Allow" - 4 - - 4
UserLevelAction == "Allow" - 4 - - 4
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
- 4 - - 4
DeliveryLocation == "Quarantine"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
- 4 - - 4
DeliveryLocation == "Quarantine"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
- 4 - - 4
DetectionMethods has "Spam"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
- 4 - - 4
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has "Spam"
- 4 - - 4
DetectionMethods has "Impersonation" - 4 - - 4
DetectionMethods contains "impersonation"
DetectionMethods contains "spoof"
- 4 - - 4
DetectionMethods has "Spoof" - 4 - - 4
ActionType == "UserSubmission"
EmailDirection == "Inbound"
- 4 - - 4
DeliveryAction !has "Blocked" - 2 - - 2
DetectionMethods contains "spoof" - 2 - - 2
DeliveryAction == "Delivered"
LatestDeliveryLocation == "Quarantine"
- 2 - - 2
LatestDeliveryLocation == "Inbox/folder" - 2 - - 2
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
SenderFromDomain !contains ".yourdomain.com"
ThreatTypes has_any "Malware"
- 2 - - 2
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Malware"
- 2 - - 2
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
SenderFromAddress !contains ".yourdomain.com"
ThreatTypes has "Phish"
- 2 - - 2
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
ThreatTypes has_any "Malware"
- 2 - - 2
DeliveryLocation in "Inbox/folder,Junk folder,Quarantine" - 2 - - 2
DetectionMethods has "File Detonation"
DetectionMethods has "URL Detonation"
- 2 - - 2
EmailDirection in "Intra-org,Outbound"
SenderFromAddress !startswith "microsoftexchange"
SenderFromAddress !startswith "postmaster@"
ThreatTypes == "Malware"
- 2 - - 2
DeliveryLocation in "Failed,Quarantine"
DetectionMethods has "Malware"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
- 2 - - 2
OrgLevelAction == "Block" - 2 - - 2
UserLevelAction == "Block" - 2 - - 2
DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
- 2 - - 2
DeliveryLocation == "Quarantine"
DetectionMethods has "Malware"
EmailDirection == "Inbound"
- 2 - - 2
ActionType == "Automated Remediation" - 2 - - 2
LatestDeliveryAction in "Hard delete,Moved to deleted items,Moved to junk folder,Soft delete" - 2 - - 2
DeliveryLocation in "Dropped,Failed,Inbox/folder,Junk folder,Quarantine"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
- 2 - - 2
DetectionMethods has "Impersonation"
DetectionMethods has "Spoof"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
- 2 - - 2
DeliveryLocation has "Inbox"
DetectionMethods has "Impersonation"
EmailDirection == "Inbound"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
- 2 - - 2
ActionType == "UserSubmission"
EmailDirection == "Intra-org"
- 2 - - 2
ActionType == "UserSubmission"
DetectionMethods has "Phish"
EmailDirection == "Inbound"
- 2 - - 2
ActionType == "UserSubmission"
DetectionMethods has "Spam"
EmailDirection == "Inbound"
- 2 - - 2
DetectionMethods has "Url"
EmailDirection == "Inbound"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
- 2 - - 2
ActionType == "ClickAllowed"
EmailDirection == "Inbound"
ThreatTypes has_any "Malware"
- 2 - - 2
DetectionMethods has "spoof" - 1 - - 1
DeliveryAction == "Delivered"
ThreatTypes has "Malware"
ThreatTypes has "Phish"
- 1 - - 1
DeliveryLocation in "Inbox/folder,Junk folder" - 1 - - 1
EmailDirection == "Inbound"
SenderIPv4 == "192.145.239.18"
- 1 - - 1
SenderFromDomain != "corporatedomain.com" - 1 - - 1
EmailDirection == "Inbound"
Subject startswith "RE:"
- 1 - - 1
AttachmentCount == "1"
EmailDirection == "Inbound"
- 1 - - 1
DeliveryAction != "Blocked"
EmailDirection == "Inbound"
SenderIPv4 startswith "27.121.5."
SenderMailFromAddress == "<>"
- 1 - - 1
Subject in "COVID-19 nCov Special info WHO,HALTH ADVISORY:CORONA VIRUS,The Truth of COVID-19,This is your order?,WTF,What the fcuk,broken file,farewell letter,good bye" - 1 - - 1
DeliveryAction == "Junked"
DetectionMethods contains "spam"
- 1 - - 1
OrgLevelAction in "Allow,Block"
OrgLevelPolicy != "Phishing simulation"
OrgLevelPolicy != "SecOps Mailbox"
OrgLevelPolicy !in "Phishing simulation,SecOps Mailbox"
UserLevelAction in "Allow,Block"
- 1 - - 1
ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user" - 1 - - 1
Total 0 260 0 0 260

ActionType

Value Connectors Content Items ASIM Parsers Other Parsers Total
UserSubmission - 10 - - 10
Automated Remediation - 2 - - 2
ClickAllowed - 2 - - 2
Add member to role - 1 - - 1
Add user - 1 - - 1
InteractiveLogon - 1 - - 1
RemoteInteractiveLogon - 1 - - 1
Reset user password - 1 - - 1
ResourceAccess - 1 - - 1
Sign-in - 1 - - 1
Update user - 1 - - 1

AttachmentCount

Value Connectors Content Items ASIM Parsers Other Parsers Total
1 - 1 - - 1

ConfidenceLevel

Value Connectors Content Items ASIM Parsers Other Parsers Total
has_any Spam - 4 - - 4

DeliveryAction

Value Connectors Content Items ASIM Parsers Other Parsers Total
Delivered - 22 - - 22
!has Blocked - 2 - - 2
!= Blocked - 1 - - 1
Junked - 1 - - 1

DeliveryLocation

Value Connectors Content Items ASIM Parsers Other Parsers Total
Quarantine - 18 - - 18
Inbox/folder - 7 - - 7
Junk folder - 7 - - 7
Failed - 6 - - 6
!= Quarantine - 4 - - 4
Dropped - 4 - - 4
has Inbox - 2 - - 2

DetectionMethods

Value Connectors Content Items ASIM Parsers Other Parsers Total
has Phish - 16 - - 16
has Malware - 12 - - 12
has Spam - 12 - - 12
has Impersonation - 8 - - 8
contains spoof - 6 - - 6
has Spoof - 6 - - 6
contains impersonation - 4 - - 4
has File Detonation - 2 - - 2
has URL Detonation - 2 - - 2
has Url - 2 - - 2
has spoof - 1 - - 1
contains spam - 1 - - 1

EmailDirection

Value Connectors Content Items ASIM Parsers Other Parsers Total
Inbound - 131 - - 131
Outbound - 15 - - 15
Intra-org - 4 - - 4

LatestDeliveryAction

Value Connectors Content Items ASIM Parsers Other Parsers Total
Hard delete - 2 - - 2
Moved to deleted items - 2 - - 2
Moved to junk folder - 2 - - 2
Soft delete - 2 - - 2

LatestDeliveryLocation

Value Connectors Content Items ASIM Parsers Other Parsers Total
Quarantine - 2 - - 2
Inbox/folder - 2 - - 2

OrgLevelAction

Value Connectors Content Items ASIM Parsers Other Parsers Total
Allow - 9 - - 9
!= Block - 8 - - 8
Block - 3 - - 3

OrgLevelPolicy

Value Connectors Content Items ASIM Parsers Other Parsers Total
!= Phishing simulation - 108 - - 108
!= SecOps Mailbox - 108 - - 108
SecOps Mailbox - 4 - - 4

SenderDisplayName

Value Connectors Content Items ASIM Parsers Other Parsers Total
contains Microsoft - 4 - - 4

SenderFromAddress

Value Connectors Content Items ASIM Parsers Other Parsers Total
!contains .yourdomain.com - 8 - - 8
!startswith microsoftexchange - 2 - - 2
!startswith postmaster@ - 2 - - 2

SenderFromDomain

Value Connectors Content Items ASIM Parsers Other Parsers Total
!contains .yourdomain.com - 2 - - 2
!= corporatedomain.com - 1 - - 1

SenderIPv4

Value Connectors Content Items ASIM Parsers Other Parsers Total
192.145.239.18 - 1 - - 1
startswith 27.121.5. - 1 - - 1

SenderMailFromAddress

Value Connectors Content Items ASIM Parsers Other Parsers Total
<> - 1 - - 1

Subject

Value Connectors Content Items ASIM Parsers Other Parsers Total
startswith RE: - 1 - - 1
COVID-19 nCov Special info WHO - 1 - - 1
HALTH ADVISORY:CORONA VIRUS - 1 - - 1
The Truth of COVID-19 - 1 - - 1
This is your order? - 1 - - 1
WTF - 1 - - 1
What the fcuk - 1 - - 1
broken file - 1 - - 1
farewell letter - 1 - - 1
good bye - 1 - - 1

ThreatTypes

Value Connectors Content Items ASIM Parsers Other Parsers Total
has Malware - 25 - - 25
has Phish - 25 - - 25
has Spam - 16 - - 16
has_any Malware - 6 - - 6
Malware - 2 - - 2

UserLevelAction

Value Connectors Content Items ASIM Parsers Other Parsers Total
!= Block - 8 - - 8
Allow - 5 - - 5
Block - 3 - - 3

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index