Skip to content

Updated and added new Hunting Queries in Microsoft Defender XDR solution. Also corrected the incorrect mapping of dataTypes: EmailEvents with connectorId: OfficeATP across multiple Hunting Queries.#14537

Open
v-utpalkumar wants to merge 2 commits into
masterfrom
V-Utpal/MicrosoftDefenderXDRSolutionHuntingQueries#14292
Open

Conversation

@v-utpalkumar

Copy link
Copy Markdown
Contributor

Change(s):

  • Updated the Hunting Query Punycode chars lookalike domains. Also added new Hunting Queries Hunt for RMM tool execution following Teams messages, Hunt for alerts correlated with Teams messages and Identify acting user for reported phish.
  • Corrected the incorrect mapping of dataTypes: EmailEvents with connectorId: OfficeATP across multiple Hunting Queries.

Reason for Change(s):

  • Updated and newley added Hunting Queries Punycode chars lookalike domains, Hunt for RMM tool execution following Teams messages, Hunt for alerts correlated with Teams messages and Identify acting user for reported phish.
  • Incorrect mapping of dataTypes: EmailEvents with connectorId: OfficeATP across multiple Hunting Queries.

Version Updated:

  • Yes

Testing Completed:

  • Yes, please refer the document attached to the work item.

Checked that the validations are passing and have addressed any issues that are present:

  • Yes

@v-utpalkumar v-utpalkumar requested review from a team as code owners June 22, 2026 15:00
@v-utpalkumar v-utpalkumar added Solution Solution specialty review needed Content-Package labels Jun 22, 2026
@v-utpalkumar v-utpalkumar changed the title Updated and added new Hunting Queries in Microsoft Defender XDR solution. Also corrected the incorrect mapping of dataTypes: EmailEvents with connectorId: OfficeATP across multiple Hunting Queries. #14439 Updated and added new Hunting Queries in Microsoft Defender XDR solution. Also corrected the incorrect mapping of dataTypes: EmailEvents with connectorId: OfficeATP across multiple Hunting Queries. Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Content-Package Solution Solution specialty review needed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants