Skip to content

Latest commit

 

History

History
25 lines (18 loc) · 758 Bytes

MalwareFileDetected.md

File metadata and controls

25 lines (18 loc) · 758 Bytes

Malware File Detected In Office 365

Query Information

MITRE ATT&CK Technique(s)

Technique ID Title Link
T1204.002 User Execution: Malicious File https://attack.mitre.org/techniques/T1204/002/

Description

This detects a malware file in your Office 365 environment. This activity does not always raise an alert.

Risk

Active malware is detected and can spread through the organisation.

References

Sentinel

OfficeActivity
| where Operation == "FileMalwareDetected"
| project-reorder TimeGenerated, OfficeWorkload, SourceFileName, OfficeObjectId, UserId