Sender recipient contact establishment
Description
This query helps in checking the sender-recipient contact establishment status
Query · kql
let emailDelivered = EmailEvents | where Timestamp < ago(30d) and DeliveryAction == "Delivered" and SenderDisplayName contains "Microsoft" | summarize count() by SenderFromAddress | where count_ > 3 // ensuring that some level of communications has occured. | project SenderFromAddress; EmailEvents | where Timestamp > ago(24hrs) | where DeliveryAction == "Delivered" and EmailDirection == "Inbound" and OrgLevelAction != "Block" and UserLevelAction != "Block" and SenderDisplayName contains "Microsoft" //Change the name here | extend NewMsg = case(Subject contains "RE:", false, Subject contains "FW:", false, true ) | project SenderDisplayName, SenderFromAddress, NetworkMessageId, SenderMailFromAddress, RecipientEmailAddress, DeliveryAction, DeliveryLocation, ThreatTypes, DetectionMethods, NewMsg, Subject | join kind=leftanti ( emailDelivered ) on SenderFromAddress | order by SenderMailFromAddress | summarize count() by SenderDisplayName, SenderFromAddress, NetworkMessageId, SenderMailFromAddress, RecipientEmailAddress, DeliveryAction, DeliveryLocation, ThreatTypes, DetectionMethods, NewMsg, Subject