Top Malware Families


Description

This query visualises total emails with Malware detections summarizing the data by ThreatNames of the malware detected.

Query · kql

EmailEvents 
| where isnotempty(ThreatNames) and ThreatTypes has "Malware" 
| summarize count() by ThreatNames 
| project ThreatNames,Emails=count_
| sort by Emails
//| render piechart // Uncomment to display as a piechart
Raw source Top Malware Families · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: 43c7c926-0bd4-41a5-a959-753db79ae470
name: Top Malware Families
description: |
  This query visualises total emails with Malware detections summarizing the data by ThreatNames of the malware detected.
description-detailed: |
  This query visualises total emails with Malware detections summarizing the data by ThreatNames of the malware detected.
  Query is also included as part of the Defender for Office 365 solution in Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - EmailEvents
tactics:
  - InitialAccess
relevantTechniques:
  - T1566
query: |
  EmailEvents 
  | where isnotempty(ThreatNames) and ThreatTypes has "Malware" 
  | summarize count() by ThreatNames 
  | project ThreatNames,Emails=count_
  | sort by Emails
  //| render piechart // Uncomment to display as a piechart
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.