Microsoft Defender for Office 365: New email submissions data in Advanced Hunting

🚨 The Signal: New Advanced Hunting tables in Defender for Office 365 provide deep visibility into email submission activity and results. This enhances threat hunting and custom detection capabilities for security operations teams.

The Impact

Security operations teams are affected by enhanced email threat visibility, reducing the risk of undetected malicious emails.

  • Security teams: Improved visibility into email submissions reduces risk of undetected threats.
  • Security analysts: New data tables enable more precise threat hunting and custom detections.
  • Incident responders: Faster correlation of submission data with other Defender XDR signals aids investigations.

The Action

  1. Review Microsoft Defender XDR Advanced Hunting documentation for SubmissionEvents and SubmissionResults tables.
  2. Develop new KQL queries and custom detection rules leveraging the SubmissionEvents and SubmissionResults tables.
  3. Integrate new submission data into existing security playbooks and incident response procedures.

Domain: Defender · Impact: medium · Workload: Microsoft Defender