Spam Detections (High) by delivery location


Description

This query visualises emails with Spam detections (High confidence) summarizing the data by Delivery Location.

Query · kql

EmailEvents
| where OrgLevelPolicy != "Phishing simulation" and OrgLevelPolicy != "SecOps Mailbox"
| where ConfidenceLevel has_any ('Spam":"High')
| summarize count() by LatestDeliveryLocation
| sort by count_ desc
| render piechart
Raw source Spam Detections (High) by delivery location · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: 42b9d582-8519-4217-a6b3-996326e55257
name: Spam Detections (High) by delivery location
description: |
  This query visualises emails with Spam detections (High confidence) summarizing the data by Delivery Location.
description-detailed: |
  This query visualises emails with Spam detections (High confidence) summarizing the data by Delivery Location which are subject to User/Admin overrides and Policy actions.
  Query is also included as part of the Defender for Office 365 solution in Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - EmailEvents
tactics:
  - InitialAccess
relevantTechniques:
  - T1566
query: |
  EmailEvents
  | where OrgLevelPolicy != "Phishing simulation" and OrgLevelPolicy != "SecOps Mailbox"
  | where ConfidenceLevel has_any ('Spam":"High')
  | summarize count() by LatestDeliveryLocation
  | sort by count_ desc
  | render piechart
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.