Post Delivery Events by Location


Description

This query visualises the amount of emails that had a post delivery action, summarizing the data daily by the final location as a result of the action

Query · kql

let TimeStart = startofday(ago(30d));
let TimeEnd = startofday(now());
let quarantine=EmailPostDeliveryEvents
| where Timestamp >= TimeStart
| where DeliveryLocation has 'Quarantine'
| make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
| extend Details = "Quarantine";
let delete=EmailPostDeliveryEvents
| where Timestamp >= TimeStart
| where DeliveryLocation has 'Delete'
| make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
| extend Details = "Delete";
let junk=EmailPostDeliveryEvents
| where Timestamp >= TimeStart
| where DeliveryLocation has 'Junk'
| make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
| extend Details = "Junk";
let inbox=EmailPostDeliveryEvents
| where Timestamp >= TimeStart
| where DeliveryLocation has 'Inbox'
| make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
| extend Details = "Inbox";
union quarantine,delete,junk,inbox
| project Count, Details, Timestamp
| render timechart
Raw source Post Delivery Events by Location · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: 9b83fc5e-1271-4a5b-af84-e7ebf5436180
name: Post Delivery Events by Location
description: |
  This query visualises the amount of emails that had a post delivery action, summarizing the data daily by the final location as a result of the action
description-detailed: |
  This query visualises the amount of emails that had a post delivery action, summarizing the data daily by the final location as a result of the action
  Query is also included as part of the Defender for Office 365 solution in Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - CloudAppEvents
tactics:
  - InitialAccess
relevantTechniques:
  - T1566
query: |
  let TimeStart = startofday(ago(30d));
  let TimeEnd = startofday(now());
  let quarantine=EmailPostDeliveryEvents
  | where Timestamp >= TimeStart
  | where DeliveryLocation has 'Quarantine'
  | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
  | extend Details = "Quarantine";
  let delete=EmailPostDeliveryEvents
  | where Timestamp >= TimeStart
  | where DeliveryLocation has 'Delete'
  | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
  | extend Details = "Delete";
  let junk=EmailPostDeliveryEvents
  | where Timestamp >= TimeStart
  | where DeliveryLocation has 'Junk'
  | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
  | extend Details = "Junk";
  let inbox=EmailPostDeliveryEvents
  | where Timestamp >= TimeStart
  | where DeliveryLocation has 'Inbox'
  | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
  | extend Details = "Inbox";
  union quarantine,delete,junk,inbox
  | project Count, Details, Timestamp
  | render timechart
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.