New URL & domain pages in Microsoft 365 Defender

Published Jun 20 2022 08:12 AM 3,043 Views
Microsoft

Want to easily investigate, take actions and pivot on URLs and domains? The new URL & domain pages will make it easier than ever. 

Try it out: URL - Microsoft 365 security

Or you can navigate through incidents, alerts, advanced hunting or by searching URL. 

 See all URL information in one placeSee all URL information in one place

 

Now you will be able to:

  • Get Domain details
    Lets you spot newly registered domains at a glance right within the page and side panel. In an investigation, newly registered domains may be a useful indicator for a suspicious domain.
  • See the URL verdict
    We’ve added a new tile that shows the Microsoft verdict for malicious URLs, indicating whether the URL is known to be bad and why (observed in phishing, malware etc.)
  • Pivot to Threat explorer
    Navigate in context to Threat explorer to hunt for emails containing this URL or domain.  
  • See related incidents
    Review incidents in your environment that involve this URL or domain. This will help correlate the URL to the attack(s) it was observed in.

List of incidents the URL was involved inList of incidents the URL was involved in

 

 

More experiences:


Pivot from the URL to related devices

In a typical investigation, you may want to pivot from the URL to other related entities to

 

Devices who had events with this URLDevices who had events with this URL

 

 

explore the scope of the attack. For example, the devices where the URL was observed may be the next thing you want to look at. The device list now shows more details about the device - such as its risk level, operating system and more – helping you prioritize the next investigation step.

To make the pivoting easier and more efficient, you can now pivot to the device timeline directly from this list, to the first or last event that involved this URL or domain. And most importantly, you can look for related devices 6 months back with one click?

 

 

New Domain (FQDN) page
Aggregates information from different observed URLs under the same fully qualified domain name into one page. You can navigate easily from any specific URL page to the related domain page, for a broader view across multiple URLs. Investigations can now make use of new aggregated data points such as the domain prevalence & incidents.

Example: Domain - Microsoft 365 security

 

New domain page – aggregated informationNew domain page – aggregated information

 

 

 

With these new features, you can now easily investigate URLs, pivot to connected devices, uplevel to investigating the domain in aggregate, and block the malicious entity.

 

See also:

1 Comment
%3CLINGO-SUB%20id%3D%22lingo-sub-3528771%22%20slang%3D%22en-US%22%3ENew%20URL%20%26amp%3B%20domain%20pages%20in%20Microsoft%20365%20Defender%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3528771%22%20slang%3D%22en-US%22%3E%3CP%3EWant%20to%20easily%20investigate%2C%20take%20actions%20and%20pivot%20on%20URLs%20and%20domains%3F%20The%20new%20URL%20%26amp%3B%20domain%20pages%20will%20make%20it%20easier%20than%20ever.%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETry%20it%20out%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsecurity.microsoft.com%2Furl%2Foverview%3Furl%3Dhttps%3A%252F%252Fdocs.microsoft.com%252Fen-us%252Fmicrosoft-365%252Fsecurity%252Fdefender%252Fmicrosoft-365-defender%253Fview%253Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EURL%20-%20Microsoft%20365%20security%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EOr%20you%20can%20navigate%20through%20incidents%2C%20alerts%2C%20advanced%20hunting%20or%20by%20searching%20URL.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22See%20all%20URL%20information%20in%20one%20place%22%20style%3D%22width%3A%20999px%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22See%20all%20URL%20information%20in%20one%20place%22%20style%3D%22width%3A%20999px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22See%20all%20URL%20information%20in%20one%20place%22%20style%3D%22width%3A%20999px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F382029i66CB7F48763EA5FC%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22URL%201.png%22%20alt%3D%22See%20all%20URL%20information%20in%20one%20place%22%20%2F%3E%3Cspan%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ESee%20all%20URL%20information%20in%20one%20place%3C%2Fspan%3E%3C%2Fspan%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ESee%20all%20URL%20information%20in%20one%20place%3C%2FSPAN%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ESee%20all%20URL%20information%20in%20one%20place%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENow%20you%20will%20be%20able%20to%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CSPAN%3E%3CSTRONG%3EGet%20Domain%20details%20%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSPAN%3ELets%20you%20spot%20newly%20registered%20domains%20at%20a%20glance%20right%20within%20the%20page%20and%20side%20panel.%20In%20an%20investigation%2C%20newly%20registered%20domains%20may%20be%20a%20useful%20indicator%20for%20a%20suspicious%20domain.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%3E%3CSTRONG%3ESee%20the%20URL%20verdict%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSPAN%3E%20%3CBR%20%2F%3E%3C%2FSPAN%3E%3CSPAN%3EWe%E2%80%99ve%20added%20a%20new%20tile%20that%20shows%20the%20Microsoft%20verdict%20for%20malicious%20URLs%2C%20indicating%20whether%20the%20URL%20is%20known%20to%20be%20bad%20and%20why%20(observed%20in%20phishing%2C%20malware%20etc.)%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%20style%3D%22font-family%3A%20inherit%3B%22%3EPivot%20to%20Threat%20explorer%3CBR%20%2F%3E%3C%2FSTRONG%3E%3CSPAN%3ENavigate%20in%20context%20to%20Threat%20explorer%20to%20hunt%20for%20emails%20containing%20this%20URL%20or%20domain.%3CEM%3E%20%26nbsp%3B%3C%2FEM%3E%3C%2FSPAN%3E%3C%2FLI%3E%0A%3CLI%3E%3CSPAN%3E%3CSTRONG%3ESee%20related%20incidents%3C%2FSTRONG%3E%3C%2FSPAN%3E%3CSPAN%3E%3CBR%20%2F%3EReview%20incidents%20in%20your%20environment%20that%20involve%20this%20URL%20or%20domain.%20This%20will%20help%20correlate%20the%20URL%20to%20the%20attack(s)%20it%20was%20observed%20in.%3C%2FSPAN%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22List%20of%20incidents%20the%20URL%20was%20involved%20in%22%20style%3D%22width%3A%20716px%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22List%20of%20incidents%20the%20URL%20was%20involved%20in%22%20style%3D%22width%3A%20716px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22List%20of%20incidents%20the%20URL%20was%20involved%20in%22%20style%3D%22width%3A%20716px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F382025iFA3A400BD3EA0D51%2Fimage-dimensions%2F716x255%3Fv%3Dv2%22%20width%3D%22716%22%20height%3D%22255%22%20role%3D%22button%22%20title%3D%22URL%202.png%22%20alt%3D%22List%20of%20incidents%20the%20URL%20was%20involved%20in%22%20%2F%3E%3Cspan%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EList%20of%20incidents%20the%20URL%20was%20involved%20in%3C%2Fspan%3E%3C%2Fspan%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EList%20of%20incidents%20the%20URL%20was%20involved%20in%3C%2FSPAN%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EList%20of%20incidents%20the%20URL%20was%20involved%20in%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%20size%3D%225%22%3E%3CSPAN%3E%3CSTRONG%3EMore%20experiences%3A%20%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%3CSTRONG%3E%3CBR%20%2F%3EPivot%20from%20the%20URL%20to%20related%20devices%3C%2FSTRONG%3E%3CBR%20%2F%3EIn%20a%20typical%20investigation%2C%20you%20may%20want%20to%20pivot%20from%20the%20URL%20to%20other%20related%20entities%20to%20%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20image-alt%3D%22Devices%20who%20had%20events%20with%20this%20URL%22%20style%3D%22width%3A%20884px%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22Devices%20who%20had%20events%20with%20this%20URL%22%20style%3D%22width%3A%20884px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22Devices%20who%20had%20events%20with%20this%20URL%22%20style%3D%22width%3A%20884px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F382026i06DC85A8F597ACB4%2Fimage-dimensions%2F884x493%3Fv%3Dv2%22%20width%3D%22884%22%20height%3D%22493%22%20role%3D%22button%22%20title%3D%22URL%20devices%20big%20.png%22%20alt%3D%22Devices%20who%20had%20events%20with%20this%20URL%22%20%2F%3E%3Cspan%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EDevices%20who%20had%20events%20with%20this%20URL%3C%2Fspan%3E%3C%2Fspan%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EDevices%20who%20had%20events%20with%20this%20URL%3C%2FSPAN%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EDevices%20who%20had%20events%20with%20this%20URL%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3Eexplore%20the%20scope%20of%20the%20attack.%20For%20example%2C%20the%20devices%20where%20the%20URL%20was%20observed%20may%20be%20the%20next%20thing%20you%20want%20to%20look%20at.%20The%20device%20list%20now%20shows%20more%20details%20about%20the%20device%20-%20such%20as%20its%20risk%20level%2C%20operating%20system%20and%20more%20%E2%80%93%20helping%20you%20prioritize%20the%20next%20investigation%20step.%20%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3ETo%20make%20the%20pivoting%20easier%20and%20more%20efficient%2C%20you%20can%20now%20pivot%20to%20the%20device%20timeline%20directly%20from%20this%20list%2C%20to%20the%20first%20or%20last%20event%20that%20involved%20this%20URL%20or%20domain.%20And%20most%20importantly%2C%20you%20can%20look%20for%20related%20devices%206%20months%20back%20with%20one%20click%3C%2FSPAN%3E%3CSPAN%3E%3F%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ENew%20Domain%20(FQDN)%20page%3C%2FSTRONG%3E%3CBR%20%2F%3EAggregates%20information%20from%20different%20observed%20URLs%20under%20the%20same%20fully%20qualified%20domain%20name%20into%20one%20page.%20You%20can%20navigate%20easily%20from%20any%20specific%20URL%20page%20to%20the%20related%20domain%20page%2C%20for%20a%20broader%20view%20across%20multiple%20URLs.%20Investigations%20can%20now%20make%20use%20of%20new%20aggregated%20data%20points%20such%20as%20the%20domain%20prevalence%20%26amp%3B%20incidents.%3C%2FP%3E%0A%3CP%3EExample%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsecurity.microsoft.com%2Fdomains%2Foverview%3FurlDomain%3Ddocs.microsoft.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EDomain%20-%20Microsoft%20365%20security%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22New%20domain%20page%20%E2%80%93%20aggregated%20information%22%20style%3D%22width%3A%20999px%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22New%20domain%20page%20%E2%80%93%20aggregated%20information%22%20style%3D%22width%3A%20999px%3B%22%3E%3Cspan%20class%3D%22lia-inline-image-display-wrapper%22%20image-alt%3D%22New%20domain%20page%20%E2%80%93%20aggregated%20information%22%20style%3D%22width%3A%20999px%3B%22%3E%3Cimg%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F382027i3DC317296DB38706%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22URL%20domain%20page%20.png%22%20alt%3D%22New%20domain%20page%20%E2%80%93%20aggregated%20information%22%20%2F%3E%3Cspan%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ENew%20domain%20page%20%E2%80%93%20aggregated%20information%3C%2Fspan%3E%3C%2Fspan%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ENew%20domain%20page%20%E2%80%93%20aggregated%20information%3C%2FSPAN%3E%3C%2FSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3ENew%20domain%20page%20%E2%80%93%20aggregated%20information%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EWith%20these%20new%20features%2C%20you%20can%20now%20easily%20investigate%20URLs%2C%20pivot%20to%20connected%20devices%2C%20uplevel%20to%20investigating%20the%20domain%20in%20aggregate%2C%20and%20block%20the%20malicious%20entity.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESee%20also%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Fdefender-endpoint%2Finvestigate-domain%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EInvestigate%20Microsoft%20Defender%20for%20Endpoint%20domains%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Fdefender-endpoint%2Finvestigate-behind-proxy%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EInvestigate%20connection%20events%20that%20occur%20behind%20forward%20proxies%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-3528771%22%20slang%3D%22en-US%22%3E%3CP%3EWant%20to%20easily%20investigate%2C%20take%20actions%20and%20pivot%20on%20URLs%20and%20domains%3F%20The%20new%20URL%20%26amp%3B%20domain%20pages%20will%20make%20it%20easier%20than%20ever.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3528771%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Defender%20for%20Endpoint%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EThreat%20Hunting%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3535397%22%20slang%3D%22en-US%22%3ERe%3A%20New%20URL%20%26amp%3B%20domain%20pages%20in%20Microsoft%20365%20Defender%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3535397%22%20slang%3D%22en-US%22%3E%3CP%3EExcellent%20contribution%20to%20the%20solution%2C%20as%20well%20as%20a%20well-written%20blog.%20Thank%20you%20very%20much.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Co-Authors
Version history
Last update:
‎Jun 20 2022 09:33 AM
Updated by: