File Malware Detections by Workload (SharePoint, OneDrive and Teams)


Description

This query summarises malware detections in files stored in SharePoint, OneDrive and Teams by the Microsoft 365 collaboration workload, using the FileMaliciousContentInfo table.

Query · kql

// FileMaliciousContentInfo records malicious-content findings for files in SharePoint, OneDrive and Teams.
FileMaliciousContentInfo
| where Timestamp > ago(30d)
| where isnotempty(ThreatTypes)
| summarize FileMalwareDetections = count(), DistinctFiles = dcount(SHA256) by Workload
| sort by FileMalwareDetections desc
Raw source File Malware Detections by Workload (SharePoint, OneDrive and Teams) · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: a895b106-6436-4586-aba7-26aee8309e64
name: File Malware Detections by Workload (SharePoint, OneDrive and Teams)
description: |
  This query summarises malware detections in files stored in SharePoint, OneDrive and Teams by the Microsoft 365 collaboration workload, using the FileMaliciousContentInfo table.
description-detailed: |
  Microsoft Defender for Office 365 and the built-in SharePoint Online antivirus scan files across Microsoft 365 collaboration workloads. This query breaks the malware detections down by workload (SharePoint, OneDrive and Microsoft Teams) to show where malicious content is most concentrated.
  This query is part of the Microsoft Defender for Office 365 Detections and Insights workbook in Microsoft Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-3-build-custom-email-security-reports-with-power-bi-and-workbooks-in-micros/4490127
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - FileMaliciousContentInfo
tactics:
  - InitialAccess
  - LateralMovement
relevantTechniques:
  - T1566
  - T1080
query: |
  // FileMaliciousContentInfo records malicious-content findings for files in SharePoint, OneDrive and Teams.
  FileMaliciousContentInfo
  | where Timestamp > ago(30d)
  | where isnotempty(ThreatTypes)
  | summarize FileMalwareDetections = count(), DistinctFiles = dcount(SHA256) by Workload
  | sort by FileMalwareDetections desc
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.