MailGuard 365 for Microsoft Sentinel

Solution: MailGuard 365

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index


Attribute Value
Publisher MailGuard 365
Support Tier Partner
Support Link https://www.mailguard365.com/support/
Categories domains
First Published 2023-05-09
Last Updated 2023-06-08
Solution Folder MailGuard 365
Marketplace Azure Marketplace · Popularity: ⚪ Very Low (0%)

Integrate MailGuard 365 with Microsoft Sentinel to accelerate threat detection and response

Contents

Data Connectors

This solution has 1 discovered data connector(s)⚠️ (not in Solution definition):

🔍 Discovered: This item was discovered by scanning the solution folder but is not listed in the Solution JSON file.

🔶 CLv1: This connector ingests into a table that uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Tables Used

This solution uses 1 table(s):

Table Used By Connectors Used By Content
MailGuard365_Threats_CL 🔶 MailGuard 365 Hunting, Workbooks

🔶 CLv1: This table uses the legacy Custom Log V1 schema format with type-suffixed column names (e.g. _s, _d, _b, _t, _g). Note: identification is based on column name suffixes which are also permitted in CLv2, so this classification may not always be accurate.

Content Items

This solution includes 4 content item(s) (0 in solution, 4 discovered 🔍):

Content Type Total In Solution Discovered
Hunting Queries 3 0 3
Workbooks 1 0 1

Hunting Queries

Name Tactics Tables Used
MailGuard 365 - High Confidence Threats ⚠️ Reconnaissance MailGuard365_Threats_CL
MailGuard 365 - Malware Threats ⚠️ InitialAccess, Reconnaissance MailGuard365_Threats_CL
MailGuard 365 - Phishing Threats ⚠️ InitialAccess, Reconnaissance, Credential Access MailGuard365_Threats_CL

Workbooks

Name Tables Used
MailGuard365Dashboard ⚠️ MailGuard365_Threats_CL

⚠️ Items marked with ⚠️ are not listed in the Solution JSON file. They were discovered by scanning the solution folder and may be legacy items, under development, or excluded from the official solution package.

Release Notes

Version Date Modified (DD-MM-YYYY) Change History
3.0.0 31-08-2023 Initial Solution Release

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Solutions Index