File Scanning Coverage (SharePoint, OneDrive and Teams)


Description

This query summarises file scanning coverage in SharePoint, OneDrive and Teams: how many files were processed, how many were found malicious, and how many were scanned with no detection, using the FileMaliciousContentInfo table.

Query · kql

FileMaliciousContentInfo
| where Timestamp > ago(30d)
| summarize FilesProcessed = count(),
            FilesWithMalware = countif(isnotempty(ThreatTypes)),
            FilesNoDetection = countif(isempty(ThreatTypes))
| extend DetectionRatePct = iif(FilesProcessed == 0, 0.0, round(100.0 * FilesWithMalware / FilesProcessed, 2))
Raw source File Scanning Coverage (SharePoint, OneDrive and Teams) · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: 7d86be89-dbdd-487e-961a-80228935563f
name: File Scanning Coverage (SharePoint, OneDrive and Teams)
description: |
  This query summarises file scanning coverage in SharePoint, OneDrive and Teams: how many files were processed, how many were found malicious, and how many were scanned with no detection, using the FileMaliciousContentInfo table.
description-detailed: |
  The FileMaliciousContentInfo table records files scanned across SharePoint, OneDrive and Teams, whether or not a threat was found. This query reports the total files processed, the number found malicious and the number scanned with no detection, with a detection rate. This scanning-coverage view is not available from action-only sources such as CloudAppEvents.
  This query is part of the Microsoft Defender for Office 365 Detections and Insights workbook in Microsoft Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-3-build-custom-email-security-reports-with-power-bi-and-workbooks-in-micros/4490127
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - FileMaliciousContentInfo
tactics:
  - InitialAccess
  - LateralMovement
relevantTechniques:
  - T1566
  - T1080
query: |
  FileMaliciousContentInfo
  | where Timestamp > ago(30d)
  | summarize FilesProcessed = count(),
              FilesWithMalware = countif(isnotempty(ThreatTypes)),
              FilesNoDetection = countif(isempty(ThreatTypes))
  | extend DetectionRatePct = iif(FilesProcessed == 0, 0.0, round(100.0 * FilesWithMalware / FilesProcessed, 2))
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.