id: 7d86be89-dbdd-487e-961a-80228935563f
name: File Scanning Coverage (SharePoint, OneDrive and Teams)
description: |
This query summarises file scanning coverage in SharePoint, OneDrive and Teams: how many files were processed, how many were found malicious, and how many were scanned with no detection, using the FileMaliciousContentInfo table.
description-detailed: |
The FileMaliciousContentInfo table records files scanned across SharePoint, OneDrive and Teams, whether or not a threat was found. This query reports the total files processed, the number found malicious and the number scanned with no detection, with a detection rate. This scanning-coverage view is not available from action-only sources such as CloudAppEvents.
This query is part of the Microsoft Defender for Office 365 Detections and Insights workbook in Microsoft Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-3-build-custom-email-security-reports-with-power-bi-and-workbooks-in-micros/4490127
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
dataTypes:
- FileMaliciousContentInfo
tactics:
- InitialAccess
- LateralMovement
relevantTechniques:
- T1566
- T1080
query: |
FileMaliciousContentInfo
| where Timestamp > ago(30d)
| summarize FilesProcessed = count(),
FilesWithMalware = countif(isnotempty(ThreatTypes)),
FilesNoDetection = countif(isempty(ThreatTypes))
| extend DetectionRatePct = iif(FilesProcessed == 0, 0.0, round(100.0 * FilesWithMalware / FilesProcessed, 2))
version: 1.0.0