Suspicious Email Delivered In Microsoft 365
Description
Detects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder. It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.
Query · sigma
selection: Workload: ThreatIntelligence Operation: TIMailData Directionality: Inbound filter_main_blocked: DeliveryAction: Blocked condition: selection and not 1 of filter_main_*
Known false positives
- Unlikely