User Email Submissions (FN) by Submission Type


Description

This query visualises the total ammount of user false negative submission by submission type, including the phish simulations reported emails

Query · kql

CloudAppEvents
| where ActionType contains "UserSubmission"
| extend SubmissionType = tostring((parse_json(RawEventData)).SubmissionType),SubmissionContentType=tostring((parse_json(RawEventData)).SubmissionContentType)
| extend User_SubmissionType=
iff(SubmissionType == "1" and ActionType == "UserSubmission" and SubmissionContentType=="Mail","User_Phish_FN",
iff(SubmissionType == "0" and ActionType == "UserSubmission" and SubmissionContentType=="Mail","User_Spam_FN",
iff(ActionType == "AttackSimUserSubmission" and SubmissionContentType=="Mail","User_AttackSim_Submission",
"Other")))
| where User_SubmissionType!="Other"
| summarize count() by User_SubmissionType
| render piechart
Raw source User Email Submissions (FN) by Submission Type · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: 0b2cbdf4-12e4-46e9-a8f6-99e559583cd7
name: User Email Submissions (FN) by Submission Type
description: |
  This query visualises the total ammount of user false negative submission by submission type, including the phish simulations reported emails
description-detailed: |
  This query visualises the total ammount of user false negative submission by submission type, including the phish simulations reported emails
  Query is also included as part of the Defender for Office 365 solution in Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - CloudAppEvents
tactics:
  - InitialAccess
relevantTechniques:
  - T1566
query: |
  CloudAppEvents
  | where ActionType contains "UserSubmission"
  | extend SubmissionType = tostring((parse_json(RawEventData)).SubmissionType),SubmissionContentType=tostring((parse_json(RawEventData)).SubmissionContentType)
  | extend User_SubmissionType=
  iff(SubmissionType == "1" and ActionType == "UserSubmission" and SubmissionContentType=="Mail","User_Phish_FN",
  iff(SubmissionType == "0" and ActionType == "UserSubmission" and SubmissionContentType=="Mail","User_Spam_FN",
  iff(ActionType == "AttackSimUserSubmission" and SubmissionContentType=="Mail","User_AttackSim_Submission",
  "Other")))
  | where User_SubmissionType!="Other"
  | summarize count() by User_SubmissionType
  | render piechart
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.