Admin Submissions by Submission State (FP)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query visualises the total amount of admin false positive submissions by the state of the submission.

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 598e2ee8-8d1d-4ded-998e-52cc43cf1160
Tactics InitialAccess
Techniques T1566
Required Connectors MicrosoftThreatProtection
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/Microsoft%20365%20Defender/Email%20and%20Collaboration%20Queries/Submissions/Admin%20Submissions%20by%20Submission%20State%20-%20FP.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries