Microsoft Sentinel high experimental kql

Mimecast Targeted Threat Protection - Impersonation Protect

'Detects a maliciously tagged impersonation.'

View Source

Detection Logic

MimecastTTPImpersonation
| where ['Tagged Malicious'] == true
| extend SenderAddress = ['Sender Address'],
  SenderIPAddress = ['Sender IP Address'],
  RecipientAddress = ['Recipient Address']

Field Validations

Loading…

Comments (0)

Loading comments...