DMARC Failure Trend


Description

This query visualises total emails with Spoof - DMARC fails summarizing the data daily.

Query · kql

let TimeStart = startofday(ago(30d));
let TimeEnd = startofday(now());
EmailEvents
| extend DMARCFail = AuthenticationDetails has_any ('DMARC":"fail') 
| make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
| render timechart
Raw source DMARC Failure Trend · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: 26ca6908-d5f1-43fa-a12b-103ba59841b5
name: DMARC Failure Trend
description: |
  This query visualises total emails with Spoof - DMARC fails summarizing the data daily.
description-detailed: |
  This query visualises total emails with Spoof - DMARC fails summarizing the data daily.
  Query is also included as part of the Defender for Office 365 solution in Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - EmailEvents
tactics:
  - InitialAccess
relevantTechniques:
  - T1566
query: |
  let TimeStart = startofday(ago(30d));
  let TimeEnd = startofday(now());
  EmailEvents
  | extend DMARCFail = AuthenticationDetails has_any ('DMARC":"fail') 
  | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
  | render timechart
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.