Top 10 External Senders (Phish)
Description
Identifies the top 10 external sender addresses delivering inbound emails classified as phishing. If you want to exclude your own organization's domains (including subdomains), add a filter after the phishing filter, e.g.: | where SenderFromAddress !contains ".yourdomain.com" (Replace "yourdomain.com" with your actual domain.) Based on Defender for Office 365 workbook: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-2-build-custom-email-security-reports-and-dashboards-with-workbooks-in-micr/4411303
Query · kql
EmailEvents | where EmailDirection == "Inbound" | where ThreatTypes has "Phish" //| where SenderFromAddress !contains ".yourdomain.com" | summarize count() by SenderFromAddress | sort by count_ desc | top 10 by count_ | render piechart