Top 10 External Senders (Spam)
Description
Identifies the top 10 external sender addresses delivering inbound emails classified as spam. To exclude your own organization's domains (including subdomains), add a filter after the spam filter, e.g.: | where SenderFromAddress !contains ".yourdomain.com" (Replace "yourdomain.com" with your actual domain.) Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
Query · kql
EmailEvents | where EmailDirection == "Inbound" | where ThreatTypes has "Spam" //| where SenderFromAddress !contains ".yourdomain.com" | summarize count() by SenderFromAddress | sort by count_ desc | top 10 by count_ | render piechart