File Malware Top Families by Microsoft Defender Detonation (SharePoint, OneDrive and Teams)


Description

This query lists the top malware families detected in files across SharePoint, OneDrive and Teams by Microsoft Defender for Office 365 (Safe Attachments detonation), using the FileMaliciousContentInfo table.

Query · kql

// DetectionMethods "detonation" indicates a Microsoft Defender for Office 365 Safe Attachments detonation verdict.
FileMaliciousContentInfo
| where Timestamp > ago(30d)
| where isnotempty(ThreatTypes)
| where tostring(DetectionMethods) has "detonation"
| summarize Files = count() by ThreatName = ThreatNames
| top 50 by Files desc
Raw source File Malware Top Families by Microsoft Defender Detonation (SharePoint, OneDrive and Teams) · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: c2c416d7-e7ac-4e1d-ad74-10d939cf0be5
name: File Malware Top Families by Microsoft Defender Detonation (SharePoint, OneDrive and Teams)
description: |
  This query lists the top malware families detected in files across SharePoint, OneDrive and Teams by Microsoft Defender for Office 365 (Safe Attachments detonation), using the FileMaliciousContentInfo table.
description-detailed: |
  Microsoft Defender for Office 365 detonates files uploaded to SharePoint, OneDrive and Teams. This query lists the malware families from those detonation verdicts. It uses the DetectionMethods field in FileMaliciousContentInfo to separate Defender for Office 365 detonation detections from the built-in SharePoint antivirus, which is more precise than inferring the source from CloudAppEvents.
  This query is part of the Microsoft Defender for Office 365 Detections and Insights workbook in Microsoft Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-3-build-custom-email-security-reports-with-power-bi-and-workbooks-in-micros/4490127
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - FileMaliciousContentInfo
tactics:
  - InitialAccess
  - LateralMovement
relevantTechniques:
  - T1566
  - T1080
query: |
  // DetectionMethods "detonation" indicates a Microsoft Defender for Office 365 Safe Attachments detonation verdict.
  FileMaliciousContentInfo
  | where Timestamp > ago(30d)
  | where isnotempty(ThreatTypes)
  | where tostring(DetectionMethods) has "detonation"
  | summarize Files = count() by ThreatName = ThreatNames
  | top 50 by Files desc
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.