File Malware Detections Over Time (SharePoint, OneDrive and Teams)


Description

This query shows the daily volume of file malware detections in SharePoint, OneDrive and Teams over the last 30 days, using the FileMaliciousContentInfo table.

Query · kql

let TimeStart = startofday(ago(30d));
let TimeEnd = startofday(now());
FileMaliciousContentInfo
| where Timestamp >= TimeStart
| where isnotempty(ThreatTypes)
| make-series FileMalwareDetections = count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
| render timechart
Raw source File Malware Detections Over Time (SharePoint, OneDrive and Teams) · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: 1e361131-c7eb-4f7a-982f-a23d5d6a3490
name: File Malware Detections Over Time (SharePoint, OneDrive and Teams)
description: |
  This query shows the daily volume of file malware detections in SharePoint, OneDrive and Teams over the last 30 days, using the FileMaliciousContentInfo table.
description-detailed: |
  Microsoft Defender for Office 365 and the built-in SharePoint Online antivirus scan files uploaded to SharePoint, OneDrive and Teams. This query charts the daily count of files detected as malicious, so spikes and trends in collaboration-platform malware can be spotted and investigated.
  This query is part of the Microsoft Defender for Office 365 Detections and Insights workbook in Microsoft Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-3-build-custom-email-security-reports-with-power-bi-and-workbooks-in-micros/4490127
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - FileMaliciousContentInfo
tactics:
  - InitialAccess
  - LateralMovement
relevantTechniques:
  - T1566
  - T1080
query: |
  let TimeStart = startofday(ago(30d));
  let TimeEnd = startofday(now());
  FileMaliciousContentInfo
  | where Timestamp >= TimeStart
  | where isnotempty(ThreatTypes)
  | make-series FileMalwareDetections = count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
  | render timechart
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.