Forum Discussion
Deleted
Nov 03, 2021Advanced hunting on email threats
Hello to all M365 Defender gurus out there. Disclaimer: I am new to M365 Defender and my question may be obvious for the seasoned professional. Situation: I am using M365 Defender's Advanced hun...
David Caddick
Nov 03, 2021Iron Contributor
Deleted
So just curious - have you tried using the "Threat Explorer"?
https://security.microsoft.com/threatexplorer
You can use this and search "All Emails" for "Ignite" & then in the lower half of the console you can choose Select All and the actions available are:
- Move & Delete
- Track & Notify
- Start new Submission
Track & Notify includes:
- Trigger Investigation
- Investigate Sender
- Investigate Recipient
- Add to remediation
- Contact recipients
Start new Submission includes:
- Report clean
- Report phishing
- Report malware
- Report spam
Hope that helps?
Deleted
Nov 04, 2021Thank you for the suggestion. I did look at "Threat Explorer" and was happy to see the actions. However, I was hoping to utilize the power of the query language to fine-tune these hunts, as it seems the "Threat Explorer" conditions have less meta-data fields available, compared to the Advanced Hunt queries. I am simply questioning, why the "take actions" within the Advanced Hunt results don't allow the same actions that "Threat Explorer" offers for emails.