Spoof Detections by Detection Technology Trend
Description
This query visualises total emails with Phish (BEC) Spoof detections by Detection Technology over time
Query · kql
let TimeStart = startofday(ago(30d)); let TimeEnd = startofday(now()); let baseQuery = EmailEvents | where DetectionMethods has "Phish"; let sdmarc=baseQuery | project Timestamp,RecipientEmailAddress,NetworkMessageId, DT=parse_json(DetectionMethods) | evaluate bag_unpack(DT) | where Phish has 'Spoof DMARC' | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d | extend Details = "Spoof DMARC"; let spoofe=baseQuery | project Timestamp,RecipientEmailAddress,NetworkMessageId, DT=parse_json(DetectionMethods) | evaluate bag_unpack(DT) | where Phish has 'Spoof external domain' | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d | extend Details = "Spoof external domain"; let spoofi=baseQuery | project Timestamp,RecipientEmailAddress,NetworkMessageId, DT=parse_json(DetectionMethods) | evaluate bag_unpack(DT) | where Phish has 'Spoof intra-org' | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d | extend Details = "Spoof intra-org"; union sdmarc, spoofe, spoofi | project Count, Details, Timestamp | render timechart