Dangerous emails with links clicked

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This will check for emails that Defend has identified as dangerous and a user has clicked a link.

Attribute Value
Type Hunting Query
Solution Egress Defend
ID 57ada8d5-7a26-4440-97fd-32c5c3fd0421
Tactics Collection
Techniques T1039
Required Connectors EgressDefend
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
EgressDefend_CL 🔶 ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Egress Defend