id: 0e4fd08d-0c0d-41c6-847d-1674e30a9e31
name: Malware Detections Trend
description: |
This query visualises total emails with Malware detections over time summarizing the data daily.
description-detailed: |
This query visualises total emails with Malware detections over time summarizing the data daily.
Query is also included as part of the Defender for Office 365 solution in Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
dataTypes:
- EmailEvents
tactics:
- InitialAccess
relevantTechniques:
- T1566
query: |
let TimeStart = startofday(ago(30d));
let TimeEnd = startofday(now());
EmailEvents
| where Timestamp >= TimeStart
| where ThreatTypes has "Malware"
| make-series MalwareDetections = count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
| render timechart
version: 1.0.0