UrlClickEvents

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Safe Links clicks from email messages, Teams, and Office 365 apps

Attribute Value
Category Security, XDR
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Lake-Only Ingestion ✓ Yes
Azure Monitor Tables Reference View Documentation
Defender XDR Advanced Hunting Schema View Documentation

Contents

Schema (20 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account
AccountUpn string User Principal Name of the account that clicked on the link.
ActionType string Indicates whether the click was allowed or blocked by 'safe links' or blocked due to a tenant policy e.g., from tenant allow block list.
AppName string The application's display name as exposed by the associated service principal.
AppVersion string Version of the client application where click occurred
DetectionMethods string Detection technology which was used to identify the threat at the time of click.
IPAddress string Public IP address of the device from which the user clicked on the link.
IsClickedThrough bool Indicates whether the user was able to click through to the original URL or was not allowed.
NetworkMessageId string The unique identifier for the email that contains the clicked link, generated by Microsoft 365.
ReportId string This is the unique identifier for a click event. Note that for clickthrough scenarios, report ID would have same value, and therefore it should be used to correlate a click event.
SourceId string Unique identifier for the source of the click
SourceSystem string The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics
TenantId string The Log Analytics workspace ID
ThreatTypes string Verdict at the time of click, which tells whether the URL led to malware, phish or other threats.
TimeGenerated datetime The date and time when the user clicked on the link. The value is identical to TimeGenerated and intended for Microsoft Defender for Endpoints queries compatibility.
Type string The name of the table
Url string The full URL that was clicked on by the user.
UrlChain string For scenarios involving redirections, it includes URLs present in the redirection chain.
Workload string The application from which the user clicked on the link, with the values being Email, Office and Teams.

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (4)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Microsoft Defender XDR

Content Items Using This Table (62)

Analytic Rules (3)

In solution Microsoft Business Applications:

Analytic Rule Selection Criteria
Power Apps - Multiple users access a malicious link after launching new app

In solution Threat Intelligence:

Analytic Rule Selection Criteria
TI Map URL Entity to UrlClickEvents

In solution Threat Intelligence (NEW):

Analytic Rule Selection Criteria
TI Map URL Entity to UrlClickEvents

Hunting Queries (58)

In solution Microsoft Defender XDR:

Hunting Query Selection Criteria
Blocked URL Clicks by Workload Workload in "Copilot,Email,Office,Teams"
Malicious Email Campaigns by Recipient URL Clicks
Rare Domains in External Teams Messages
Teams URL clicks actions summarized by URLs clicked on Workload == "Teams"
Teams URL clicks through actions on Phish or Malware URLs summarized by URLs ThreatTypes in "Malware,Phish"
Teams blocked URL clicks daily trend
Top 10 Users clicking on malicious URLs in Teams ThreatTypes in "Malware,Phish"
Top 20 Malicious URLs by Clicks
Top Clicks on Malicious URLs
Top malicious URLs clicked by users in Teams
URL Click-Through by Workload IsClickedThrough != "0"
URL Threat Protection Summary

GitHub Only:

Hunting Query Selection Criteria
Blocked Clicks Trend
Blocked Clicks Trend
Blocked URL Clicks by Workload Workload in "Copilot,Email,Office,Teams"
End user malicious clicks ThreatTypes contains "Phish"
End user malicious clicks ThreatTypes contains "Phish"
MDO_URLClickedinEmail
MDO_URLClickedinEmail
Malicious Clicks allowed (click-through) IsClickedThrough == "1"
Malicious Clicks allowed (click-through) IsClickedThrough == "1"
Malicious Email Campaigns by Recipient URL Clicks
Malicious URL Clicks by workload
Malicious URL Clicks by workload
Possible device code phishing attempts
Possible device code phishing attempts
Rare Domains in External Teams Messages
Teams URL clicks actions summarized by URLs clicked on Workload == "Teams"
Teams URL clicks through actions on Phish or Malware URLs summarized by URLs ThreatTypes in "Malware,Phish"
Teams blocked URL clicks daily trend
Top 10 Users clicking on Malicious URLs (Malware) ThreatTypes has "Malware"
Top 10 Users clicking on Malicious URLs (Malware) ThreatTypes has "Malware"
Top 10 Users clicking on Malicious URLs (Malware+Phish+Spam) ThreatTypes has_any "Malware"
Top 10 Users clicking on Malicious URLs (Malware+Phish+Spam) ThreatTypes has_any "Malware"
Top 10 Users clicking on Malicious URLs (Phish) ThreatTypes has "Phish"
Top 10 Users clicking on Malicious URLs (Phish) ThreatTypes has "Phish"
Top 10 Users clicking on Malicious URLs (Spam) ThreatTypes has "Spam"
Top 10 Users clicking on Malicious URLs (Spam) ThreatTypes has "Spam"
Top 10 Users clicking on malicious URLs in Teams ThreatTypes in "Malware,Phish"
Top 20 Malicious URLs by Clicks
Top Clicks on Malicious URLs
Top malicious URLs clicked by users in Teams
URL Click attempts by threat type
URL Click attempts by threat type
URL Click-Through by Workload IsClickedThrough != "0"
URL Clicks by Action
URL Clicks by Action
URL Threat Protection Summary
URL click count by click action
URL click count by click action
URL clicks actions by URL
URL clicks actions by URL
User clicked through events ThreatTypes has "Phish"
User clicked through events ThreatTypes has "Phish"
User clicks on malicious inbound emails
User clicks on malicious inbound emails
User clicks on phishing URLs in emails ThreatTypes has "Phish"
User clicks on phishing URLs in emails ThreatTypes has "Phish"

Workbooks (1)

In solution Microsoft Defender XDR:

Workbook Selection Criteria
MicrosoftDefenderForOffice365detectionsandinsights

Selection Criteria Summary (10 criteria, 26 total references)

References by type: 0 connectors, 26 content items, 0 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
ThreatTypes has "Phish" - 6 - - 6
ThreatTypes in "Malware,Phish" - 4 - - 4
ThreatTypes has_any "Malware" - 2 - - 2
Workload == "Teams" - 2 - - 2
IsClickedThrough == "1" - 2 - - 2
ThreatTypes has "Malware" - 2 - - 2
ThreatTypes has "Spam" - 2 - - 2
Workload in "Copilot,Email,Office,Teams" - 2 - - 2
ThreatTypes contains "Phish" - 2 - - 2
IsClickedThrough != "0" - 2 - - 2
Total 0 26 0 0 26

IsClickedThrough

Value Connectors Content Items ASIM Parsers Other Parsers Total
1 - 2 - - 2
!= 0 - 2 - - 2

ThreatTypes

Value Connectors Content Items ASIM Parsers Other Parsers Total
has Phish - 6 - - 6
Malware - 4 - - 4
Phish - 4 - - 4
has_any Malware - 2 - - 2
has Malware - 2 - - 2
has Spam - 2 - - 2
contains Phish - 2 - - 2

Workload

Value Connectors Content Items ASIM Parsers Other Parsers Total
Teams - 4 - - 4
Copilot - 2 - - 2
Email - 2 - - 2
Office - 2 - - 2

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index