Post Delivery Events by ZAP type


Description

This query visualises the daily amount of emails that had a post delivery action from zero-hour auto purge, summarizing by phish,spam or malware detection action

Query · kql

let TimeStart = startofday(ago(30d));
let TimeEnd = startofday(now());
let baseQuery = EmailPostDeliveryEvents
| where Timestamp >= TimeStart
| where ActionType has "ZAP";
let szap=baseQuery
| where ActionType has 'Spam ZAP'
| make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
| extend Details = "Spam ZAP";
let pzap=baseQuery
| where ActionType has 'Phish ZAP'
| make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
| extend Details = "Phish ZAP";
let mzap=baseQuery
| where ActionType has 'Malware ZAP'
| make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
| extend Details = "Malware ZAP";
union szap,pzap,mzap
| project Count, Details, Timestamp
| render timechart
Raw source Post Delivery Events by ZAP type · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: c0efc072-fce7-46c2-83a1-51e8a9e6a1e1
name: Post Delivery Events by ZAP type
description: |
  This query visualises the daily amount of emails that had a post delivery action from zero-hour auto purge, summarizing by phish,spam or malware detection action
description-detailed: |
  This query visualises the daily amount of emails that had a post delivery action from zero-hour auto purge, summarizing by phish,spam or malware detection action in Defender for Office 365
  Query is also included as part of the Defender for Office 365 solution in Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
requiredDataConnectors:
  - connectorId: MicrosoftThreatProtection
    dataTypes:
      - EmailPostDeliveryEvents
tactics:
  - InitialAccess
relevantTechniques:
  - T1566
query: |
  let TimeStart = startofday(ago(30d));
  let TimeEnd = startofday(now());
  let baseQuery = EmailPostDeliveryEvents
  | where Timestamp >= TimeStart
  | where ActionType has "ZAP";
  let szap=baseQuery
  | where ActionType has 'Spam ZAP'
  | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
  | extend Details = "Spam ZAP";
  let pzap=baseQuery
  | where ActionType has 'Phish ZAP'
  | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
  | extend Details = "Phish ZAP";
  let mzap=baseQuery
  | where ActionType has 'Malware ZAP'
  | make-series Count= count() default = 0 on Timestamp from TimeStart to TimeEnd step 1d
  | extend Details = "Malware ZAP";
  union szap,pzap,mzap
  | project Count, Details, Timestamp
  | render timechart
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.