Mail reply to new domain


Description

This query helps reviewing mail that is likely a reply but there is no history of the people chatting and the domain is new

Query · kql

let emailDelivered = EmailEvents
| where Timestamp < ago(4hrs)
and DeliveryAction == "Delivered"
| extend Pair = strcat(SenderMailFromAddress,"|",RecipientEmailAddress)
| distinct Pair;
let EmailDomains = EmailEvents
| where Timestamp < ago(4hrs)
and DeliveryAction == "Delivered"
| distinct SenderFromDomain;
EmailEvents 
| where Timestamp >= ago(4hrs)
| where DeliveryLocation != "Quarantine"
 and EmailDirection == "Inbound" 
 and OrgLevelAction != "Block"
 and UserLevelAction != "Block"
| extend NewMsg = case(Subject contains "RE:", false, Subject contains "FW:", false, true )
| project Pair = strcat(SenderMailFromAddress,"|",RecipientEmailAddress), NetworkMessageId, SenderFromDomain, SenderMailFromAddress, RecipientEmailAddress, DeliveryAction, ThreatTypes, DetectionMethods, NewMsg, Subject 
| join kind=leftouter ( emailDelivered ) on Pair
| order by SenderMailFromAddress
| where NewMsg == false
and Pair1 == ""
| join kind=leftouter (EmailDomains) on SenderFromDomain
| where SenderFromDomain1 == ""
| distinct Pair, NetworkMessageId, SenderFromDomain, SenderMailFromAddress, RecipientEmailAddress, DeliveryAction, ThreatTypes, DetectionMethods, NewMsg, Subject
Raw source Mail reply to new domain · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: da7b973a-0045-4fd6-9161-269369336d24
name: Mail reply to new domain
description: |
  This query helps reviewing mail that is likely a reply but there is no history of the people chatting and the domain is new
description-detailed: |
  This query helps reviewing mail that is likely a reply but there is no history of the people chatting and the domain is new
requiredDataConnectors:
  - connectorId: MicrosoftThreatProtection
    dataTypes:
      - EmailEvents
tactics:
  - InitialAccess
relevantTechniques:
  - T1566
query: |
  let emailDelivered = EmailEvents
  | where Timestamp < ago(4hrs)
  and DeliveryAction == "Delivered"
  | extend Pair = strcat(SenderMailFromAddress,"|",RecipientEmailAddress)
  | distinct Pair;
  let EmailDomains = EmailEvents
  | where Timestamp < ago(4hrs)
  and DeliveryAction == "Delivered"
  | distinct SenderFromDomain;
  EmailEvents 
  | where Timestamp >= ago(4hrs)
  | where DeliveryLocation != "Quarantine"
   and EmailDirection == "Inbound" 
   and OrgLevelAction != "Block"
   and UserLevelAction != "Block"
  | extend NewMsg = case(Subject contains "RE:", false, Subject contains "FW:", false, true )
  | project Pair = strcat(SenderMailFromAddress,"|",RecipientEmailAddress), NetworkMessageId, SenderFromDomain, SenderMailFromAddress, RecipientEmailAddress, DeliveryAction, ThreatTypes, DetectionMethods, NewMsg, Subject 
  | join kind=leftouter ( emailDelivered ) on Pair
  | order by SenderMailFromAddress
  | where NewMsg == false
  and Pair1 == ""
  | join kind=leftouter (EmailDomains) on SenderFromDomain
  | where SenderFromDomain1 == ""
  | distinct Pair, NetworkMessageId, SenderFromDomain, SenderMailFromAddress, RecipientEmailAddress, DeliveryAction, ThreatTypes, DetectionMethods, NewMsg, Subject
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.