Forum Discussion

immanuelpeschenthyssenkruppcom's avatar
Apr 30, 2020

Direct Link to Threat Explorer Results

Dear community,

 

I'm working in Cyber Security Operations Center. In our daily work we need to investigate O365 alerts. What we currently just have is a link to the Azure Security Portal (AppSecurityPortal), but there are no detailed information about a detected phishing are malware mail like. Therefore we would like to use a direct link to https://protection.office.com instead. So far I know from the raw date on the AppSecurityPortal is that a direct link to specific message is possible via

 

"EventDeepLink": "https://protection.office.com/?hash=/threatexplorer?messageParams=<id>,2020-04-29T00:00:00,2020-04-29T23:59:59&view=Phish"

 

But what we use in investigation is for example a direct link to get the result for e.g. all mails with a specific subject or from a specific sender. I know we can do it manually via the website, but a direct link placed in our internal ticketing system would help our analysts to speed up the investigation.

 

Maybe you know how i can handover parameters in URL in order to start directly a search like this.

 

In addition we would like to know the same for the CloudAppSecurityPortal Activity Log:

we know that we can directly jump to all activities related to a specific IP with the following:

https://<companyname>.portal.cloudappsecurity.com/#/audits?ip.address=eq(<ip>,)

 

But we would also like to know here how to search directly for specific user or mail address.

 

Many thanks for your help!

 

Regards

Immanuel Peschen

Resources