--- name: email-threat-posture description: 'Generate email threat protection reports and assess email security posture. Triggers on keywords like "email threat report", "email security posture", "phishing report", "MDO report", "Defender for Office 365 report", "ZAP effectiveness", "Safe Links report", "DMARC report", "spam report", "email volume report". Queries EmailEvents, EmailPostDeliveryEvents, UrlClickEvents, and EmailAttachmentInfo in Advanced Hunting for a posture assessment covering inbound mail flow, threat composition, phishing detection, email authentication (DMARC/DKIM/SPF), post-delivery remediation (ZAP), Safe Links click protection, attachment analysis, detection method effectiveness, and delivery disposition. Supports inline chat, markdown file, and SVG dashboard output.' threat_pulse_domains: [email] drill_down_prompt: 'Run email threat posture report β€” phishing trends, delivery gaps, protection effectiveness' --- # Email Threat Protection Posture β€” Instructions ## Purpose This skill generates an **Email Threat Protection Posture Report** using Microsoft Defender for Office 365 (MDO) telemetry available through Advanced Hunting. It provides C-level visibility into how effectively the organization's email security stack is detecting, blocking, and remediating email-based threats. **What this skill covers:** | Domain | Key Questions Answered | |--------|----------------------| | πŸ“¬ **Mail Flow Overview** | How many inbound emails? What's the daily trend? Who are the top senders? | | πŸ›‘οΈ **Threat Composition** | How many phishing, spam, and malware threats were detected? | | 🎯 **Phishing Protection** | How many phishing emails were blocked vs delivered? Who are the most targeted users? | | πŸ” **Email Authentication** | What are the DMARC/DKIM/SPF/CompAuth pass rates? Which domains fail authentication? | | 🧹 **Post-Delivery Remediation** | How effective is ZAP? How many remediations succeeded vs failed? | | πŸ”— **Safe Links Protection** | How many URL clicks were scanned? Were any phishing clicks allowed through? | | πŸ“Ž **Attachment Analysis** | What attachment types are flowing through email? Were any malicious? | | πŸ“Š **Detection Methods** | What detection technologies are catching threats (URL detonation, fingerprinting, etc.)? | | πŸ“¦ **Delivery Disposition** | Where do emails end up β€” inbox, junk, quarantine, blocked? | | 🚨 **MDO Incidents** | How many security incidents were generated by Defender for Office? What severity, status, and types? | **Data sources:** `EmailEvents`, `EmailPostDeliveryEvents`, `UrlClickEvents`, `EmailAttachmentInfo`, `SecurityAlert`, `SecurityIncident` (Advanced Hunting) **References:** - [Microsoft Docs β€” EmailEvents table](https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-emailevents-table) - [Microsoft Docs β€” EmailPostDeliveryEvents table](https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-emailpostdeliveryevents-table) - [Microsoft Docs β€” UrlClickEvents table](https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-urlclickevents-table) - [Microsoft Docs β€” EmailAttachmentInfo table](https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-emailattachmentinfo-table) - [MDO Efficacy Query β€” Microsoft Learn](https://learn.microsoft.com/en-us/defender-office-365/reports-mdo-email-collaboration-dashboard#appendix-advanced-hunting-efficacy-query-in-defender-for-office-365-plan-2) ### πŸ”΄ URL Registry β€” Canonical Links for Report Generation **MANDATORY:** When generating reports, copy URLs **verbatim** from this registry. NEVER construct, guess, or paraphrase a URL. | Label | Canonical URL | |-------|---------------| | `DOCS_EMAILEVENTS` | `https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-emailevents-table` | | `DOCS_EMAILPOSTDELIVERY` | `https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-emailpostdeliveryevents-table` | | `DOCS_URLCLICKEVENTS` | `https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-urlclickevents-table` | | `DOCS_EMAILATTACHMENTINFO` | `https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-emailattachmentinfo-table` | | `DOCS_MDO_EFFICACY` | `https://learn.microsoft.com/en-us/defender-office-365/reports-mdo-email-collaboration-dashboard#appendix-advanced-hunting-efficacy-query-in-defender-for-office-365-plan-2` | | `DOCS_MDO_OVERVIEW` | `https://learn.microsoft.com/en-us/defender-office-365/mdo-about` | | `DOCS_SECURITY_ALERT` | `https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/microsoft-sentinel-security-alert` | | `DOCS_ZAP` | `https://learn.microsoft.com/en-us/defender-office-365/zero-hour-auto-purge` | | `DOCS_SAFE_LINKS` | `https://learn.microsoft.com/en-us/defender-office-365/safe-links-about` | --- ## πŸ“‘ TABLE OF CONTENTS 1. **[Critical Workflow Rules](#-critical-workflow-rules---read-first-)** β€” Mandatory rules 2. **[Email Protection Score Formula](#email-protection-score-formula)** β€” Composite posture scoring 3. **[Execution Workflow](#execution-workflow)** β€” Phase-by-phase query plan 4. **[Sample KQL Queries](#sample-kql-queries)** β€” All queries (Q1–Q14) 5. **[Output Modes](#output-modes)** β€” Inline vs Markdown report 6. **[Inline Report Template](#inline-report-template)** β€” Chat-rendered format 7. **[Markdown File Report Template](#markdown-file-report-template)** β€” Disk-saved format 8. **[Known Pitfalls](#known-pitfalls)** β€” Schema quirks and edge cases 9. **[Quality Checklist](#quality-checklist)** β€” Pre-delivery validation 10. **[SVG Dashboard Generation](#svg-dashboard-generation)** β€” Visual dashboard from report --- ## ⚠️ CRITICAL WORKFLOW RULES - READ FIRST ⚠️ 1. **Use `RunAdvancedHuntingQuery` by default** β€” EmailEvents and related tables are XDR-native tables available in Advanced Hunting. Use `Timestamp` as the datetime column. If a query fails in AH, fall back to Sentinel Data Lake (`query_lake`) using `TimeGenerated`. 2. **Default lookback: 7 days** β€” Unless the user specifies a different period. This provides a meaningful weekly snapshot for executive reporting while staying within AH's 30-day retention. 3. **ASK the user for output format** before generating the report: - **Inline chat summary** (quick review in chat) - **Markdown file report** (detailed, archived to `reports/email-threat-posture/`) - **Both** (markdown + inline summary) 4. **β›” MANDATORY: Evidence-based analysis only** β€” Report ONLY what query results show. Use the explicit absence pattern (`βœ… No [finding] detected`) when queries return 0 results. Never fabricate data. 5. **Run queries in parallel batches** where possible β€” Phase 1 queries (Q1–Q4) are independent. Phase 2 queries (Q5–Q8) are independent. Phase 3 queries (Q9–Q12) are independent. 6. **PII handling** β€” Do NOT include recipient email addresses in inline reports or markdown files. Aggregate by domain or use anonymized references (e.g., "2 users in the contoso.com domain"). Top sender domains from external sources are acceptable. 7. **Percentages must be grounded** β€” Always show both the percentage AND the raw count (e.g., "99.8% clean (5,851 of 5,864)"). --- ## Email Protection Score Formula The Email Protection Score is a composite posture indicator summarizing the effectiveness of email security controls. Higher scores indicate stronger protection (inverse of a risk score). ### Scoring Dimensions $$ \text{EmailProtectionScore} = \sum_{i} \text{DimensionScore}_i $$ Each dimension contributes 0–20 points to a maximum of 100: | Dimension | Max | 🟒 High (16–20) | 🟑 Medium (8–15) | πŸ”΄ Low (0–7) | |-----------|-----|-----------------|-------------------|--------------| | **Threat Block Rate** | 20 | β‰₯95% of threats not in inbox (post-ZAP final state) | 80–94% remediated | <80% remediated (threats remain in inbox) | | **Email Authentication** | 20 | SPF+DMARC+DKIM all β‰₯95% | Any one 80–94% | Any one <80% | | **ZAP Effectiveness** | 20 | β‰₯95% ZAP success rate + 0 failed ZAPs | 80–94% success OR 1–2 failures | <80% success OR β‰₯3 failures | | **Safe Links Protection** | 20 | 0 phishing click-throughs AND active scanning | 1–2 phishing click-throughs | β‰₯3 phishing click-throughs OR no scanning | | **Phishing Delivery Rate** | 20 | 0 phishing emails delivered (post-ZAP) | 1–5 phishing delivered (post-ZAP) | >5 phishing still in mailboxes (post-ZAP) | ### Interpretation Scale | Score | Rating | Action | |-------|--------|--------| | **85–100** | βœ… Strong | Excellent posture β€” maintain current configurations | | **65–84** | 🟑 Good | Minor gaps β€” review flagged dimensions | | **45–64** | 🟠 Needs Improvement | Multiple weaknesses β€” prioritize remediation | | **0–44** | πŸ”΄ Critical | Significant exposure β€” immediate action required | --- ## Execution Workflow ### Phase 0: Prerequisites 1. Confirm `RunAdvancedHuntingQuery` is available (EmailEvents tables are AH-native) 2. Ask user for output format (inline / markdown / both) 3. Confirm lookback period (default: 7 days) ### Phase 1: Mail Flow & Threat Overview (Q1–Q4) **Run in parallel β€” no dependencies between queries.** | Query | Purpose | |-------|---------| | Q1 | Inbound email summary with threat breakdown | | Q2 | Email volume trend by day | | Q3 | Delivery action and location breakdown | | Q4 | Detection methods breakdown | ### Phase 2: Protection Effectiveness (Q5–Q8) **Run in parallel β€” no dependencies between queries.** | Query | Purpose | |-------|---------| | Q5 | Email authentication pass rates (DMARC/DKIM/SPF/CompAuth) | | Q6 | ZAP and post-delivery remediation summary | | Q7 | Safe Links click activity summary | | Q8 | Phishing emails delivered (not blocked) | ### Phase 3: Deep Dives & Governance (Q9–Q12) **Run in parallel β€” no dependencies between queries.** | Query | Purpose | |-------|---------| | Q9 | Top phishing sender domains | | Q10 | Most targeted recipients (aggregated) | | Q11 | Attachment type distribution | | Q12 | Post-ZAP threat state (latest delivery location) | ### Phase 4: MDO Security Incidents (Q13–Q14) **Run in parallel β€” no dependencies between queries.** | Query | Purpose | |-------|--------| | Q13 | MDO incident summary by severity and status | | Q14 | MDO incident type breakdown (top alert-driven incidents) | > **⚠️ SecurityAlert.Status is IMMUTABLE** β€” always "New" regardless of actual state. These queries use the canonical SecurityAlertβ†’SecurityIncident join to get real Status and Classification from the SecurityIncident table. See copilot-instructions.md Known Table Pitfalls. ### Phase 5: Score Computation & Report Generation 1. **Compute per-dimension scores** from Phase 1–4 data 2. **Sum dimension scores** for composite Email Protection Score 3. **Generate report** in requested output mode 4. **Offer SVG dashboard** if not already requested --- ## Sample KQL Queries > **All queries below are verified against the EmailEvents family of tables. Use them exactly as written, substituting only the lookback period where noted. These queries use `Timestamp` for Advanced Hunting. If falling back to Data Lake, replace `Timestamp` with `TimeGenerated`.** ### Query 1: Inbound Email Summary with Threat Breakdown ```kql EmailEvents | where Timestamp > ago(7d) | where EmailDirection == "Inbound" | summarize TotalInbound = count(), Clean = countif(isempty(ThreatTypes)), Phish = countif(ThreatTypes has "Phish"), Malware = countif(ThreatTypes has "Malware"), Spam = countif(ThreatTypes has "Spam"), HighConfPhish = countif(ConfidenceLevel has "High" and ThreatTypes has "Phish"), Blocked = countif(DeliveryAction == "Blocked"), Delivered = countif(DeliveryAction == "Delivered"), Junked = countif(DeliveryAction == "Junked"), DistinctSenders = dcount(SenderFromAddress), DistinctRecipients = dcount(RecipientEmailAddress) | project TotalInbound, Clean, Phish, Malware, Spam, HighConfPhish, Blocked, Delivered, Junked, DistinctSenders, DistinctRecipients ``` ### Query 2: Email Volume Trend by Day ```kql EmailEvents | where Timestamp > ago(7d) | summarize Inbound = countif(EmailDirection == "Inbound"), Outbound = countif(EmailDirection == "Outbound"), IntraOrg = countif(EmailDirection == "Intra-org") by Day = bin(Timestamp, 1d) | order by Day asc ``` ### Query 3: Delivery Action & Location Breakdown ```kql EmailEvents | where Timestamp > ago(7d) | where EmailDirection == "Inbound" | summarize Count = count() by DeliveryAction, DeliveryLocation | order by Count desc ``` ### Query 4: Detection Methods Breakdown ```kql EmailEvents | where Timestamp > ago(7d) | where isnotempty(DetectionMethods) and DetectionMethods != "{}" | extend DetMethods = parse_json(DetectionMethods) | extend FirstDetection = tostring(bag_keys(DetMethods)[0]) | extend FirstSubcategory = iif( FirstDetection != "" and array_length(DetMethods[FirstDetection]) > 0, strcat(FirstDetection, ": ", tostring(DetMethods[FirstDetection][0])), FirstDetection) | summarize Count = count() by FirstSubcategory | order by Count desc ``` ### Query 5: Email Authentication Pass Rates ```kql EmailEvents | where Timestamp > ago(7d) | where EmailDirection == "Inbound" | extend AuthDetails = parse_json(AuthenticationDetails) | extend DMARC = tostring(AuthDetails.DMARC), DKIM = tostring(AuthDetails.DKIM), SPF = tostring(AuthDetails.SPF), CompAuth = tostring(AuthDetails.CompAuth) | summarize TotalEmails = count(), DMARCPass = countif(DMARC == "pass"), DMARCFail = countif(DMARC == "fail"), DKIMPass = countif(DKIM == "pass"), DKIMFail = countif(DKIM == "fail"), SPFPass = countif(SPF == "pass"), SPFFail = countif(SPF == "fail"), CompAuthPass = countif(CompAuth has "pass"), CompAuthFail = countif(CompAuth == "fail") ``` ### Query 6: ZAP & Post-Delivery Remediation Summary ```kql EmailPostDeliveryEvents | where Timestamp > ago(7d) | summarize TotalActions = count(), PhishZAP = countif(ActionType == "Phish ZAP"), MalwareZAP = countif(ActionType == "Malware ZAP"), SpamZAP = countif(ActionType == "Spam ZAP"), ThreatZAPTotal = countif(ActionType in ("Phish ZAP", "Malware ZAP", "Spam ZAP")), ManualRemediation = countif(ActionType has "Admin"), SuccessCount = countif(ActionResult == "Success"), ErrorCount = countif(ActionResult == "Error") | project TotalActions, PhishZAP, MalwareZAP, SpamZAP, ThreatZAPTotal, ManualRemediation, SuccessCount, ErrorCount ``` ### Query 7: Safe Links Click Activity Summary ```kql UrlClickEvents | where Timestamp > ago(7d) | summarize TotalClicks = count(), BlockedClicks = countif(ActionType == "ClickBlocked"), AllowedClicks = countif(ActionType == "ClickAllowed"), ClickedThrough = countif(IsClickedThrough == true), PhishClicks = countif(ThreatTypes has "Phish"), DistinctUrls = dcount(Url), DistinctUsers = dcount(AccountUpn) ``` ### Query 8: Phishing Emails Delivered (Not Blocked) ```kql EmailEvents | where Timestamp > ago(7d) | where ThreatTypes has "Phish" | where DeliveryAction == "Delivered" or LatestDeliveryAction == "Delivered" | summarize DeliveredPhish = count(), DistinctRecipients = dcount(RecipientEmailAddress), DistinctSenders = dcount(SenderFromAddress), Subjects = make_set(Subject, 5) ``` ### Query 9: Top Phishing Sender Domains ```kql EmailEvents | where Timestamp > ago(7d) | where ThreatTypes has "Phish" | summarize Count = count(), DistinctRecipients = dcount(RecipientEmailAddress), DeliveredCount = countif(DeliveryAction == "Delivered" or LatestDeliveryAction == "Delivered") by SenderFromDomain | top 10 by Count ``` ### Query 10: Most Targeted Recipients (Aggregated by Domain) ```kql EmailEvents | where Timestamp > ago(7d) | where isnotempty(ThreatTypes) and EmailDirection == "Inbound" | extend RecipientDomain = tostring(split(RecipientEmailAddress, "@")[1]) | summarize ThreatCount = count(), PhishCount = countif(ThreatTypes has "Phish"), SpamCount = countif(ThreatTypes has "Spam"), MalwareCount = countif(ThreatTypes has "Malware"), DistinctRecipients = dcount(RecipientEmailAddress) by RecipientDomain | order by ThreatCount desc ``` ### Query 11: Attachment Type Distribution ```kql EmailAttachmentInfo | where Timestamp > ago(7d) | summarize Count = count(), DistinctFiles = dcount(FileName), ThreatCount = countif(isnotempty(ThreatTypes)) by FileType | order by Count desc | take 15 ``` ### Query 12: Post-ZAP Threat State (Latest Delivery Location) ```kql EmailEvents | where Timestamp > ago(7d) | where EmailDirection == "Inbound" | where isnotempty(ThreatTypes) | summarize Count = count() by LatestDeliveryAction, LatestDeliveryLocation, ThreatTypes | order by Count desc ``` ### Query 13: MDO Incident Summary by Severity and Status > Uses the canonical SecurityAlertβ†’SecurityIncident join. Filters to `ProductName == "Office 365 Advanced Threat Protection"` and excludes Communication Compliance alerts (`CC_` prefix). ```kql let MDOAlerts = SecurityAlert | where TimeGenerated > ago(7d) | where ProductName == "Office 365 Advanced Threat Protection" | where AlertName !startswith "CC_" | summarize arg_max(TimeGenerated, *) by SystemAlertId | project SystemAlertId; SecurityIncident | where CreatedTime > ago(7d) | summarize arg_max(TimeGenerated, *) by IncidentNumber | mv-expand AlertId = AlertIds | extend AlertId = tostring(AlertId) | join kind=inner MDOAlerts on $left.AlertId == $right.SystemAlertId | summarize IncidentCount = dcount(IncidentNumber) by Severity, Status, Classification | order by Severity asc, IncidentCount desc ``` ### Query 14: MDO Incident Type Breakdown (Top Alert-Driven Incidents) > Groups incidents by title and alert composition to show the most common MDO-generated incident types. ```kql let MDOAlerts = SecurityAlert | where TimeGenerated > ago(7d) | where ProductName == "Office 365 Advanced Threat Protection" | where AlertName !startswith "CC_" | summarize arg_max(TimeGenerated, *) by SystemAlertId | project SystemAlertId, AlertName, AlertSeverity, ProductName; SecurityIncident | where CreatedTime > ago(7d) | summarize arg_max(TimeGenerated, *) by IncidentNumber | mv-expand AlertId = AlertIds | extend AlertId = tostring(AlertId) | join kind=inner MDOAlerts on $left.AlertId == $right.SystemAlertId | summarize IncidentCount = dcount(IncidentNumber), AlertCount = count(), OpenCount = dcountif(IncidentNumber, Status == "New" or Status == "Active"), ClosedCount = dcountif(IncidentNumber, Status == "Closed"), TruePositives = dcountif(IncidentNumber, Classification == "TruePositive") by AlertName, Severity | order by IncidentCount desc | take 10 ``` --- ## Output Modes ### Mode 1: Inline Chat Summary Render the full analysis directly in the chat response. Best for quick review and C-level briefings. ### Mode 2: Markdown File Report Save a comprehensive report to disk at: ``` reports/email-threat-posture/Email_Threat_Protection_Report_YYYYMMDD_HHMMSS.md ``` ### Mode 3: Both Generate the markdown file AND provide an inline summary in chat. **Always ask the user which mode before generating output.** --- ## Inline Report Template Render the following sections in order. Omit sections only if explicitly noted as conditional. > **πŸ”΄ URL Rule:** All hyperlinks in the report MUST be copied verbatim from the [URL Registry](#-url-registry--canonical-links-for-report-generation) above. Do NOT generate, recall from memory, or paraphrase any URL. If a needed URL is not in the registry, use plain text (no hyperlink). ````markdown # πŸ“§ Email Threat Protection Report **Generated:** YYYY-MM-DD HH:MM UTC **Data Source:** Microsoft Defender for Office 365 (Advanced Hunting) **Analysis Period:** β†’ ( days) **Protected Mailboxes:** **Total Inbound Emails:** **Email Protection Score:** /100 β€” --- ## Executive Summary <2-3 sentences: total inbound volume, threat detection rate, key findings, overall posture rating> **Email Protection Score:** 🟒/🟑/🟠/πŸ”΄ (/100) --- ## Key Metrics | Metric | Value | |--------|-------| | Total Inbound Emails | | | Clean Email Rate | % ( of ) | | Threats Detected | (Phish: , Spam: , Malware: ) | | Threats Blocked Pre-Delivery | | | Phishing Delivered (Now Remediated) | | | Threat ZAP Actions | (Phish: , Malware: , Spam: ) | | Total Post-Delivery Actions | (includes system events) | | ZAP Success Rate | % (Failed: ) | | Threats Still in Mailboxes (Post-ZAP) | (Phish: , Spam: ) | | Safe Links Clicks Scanned | | | Phishing Click-Throughs | | | Distinct Senders | | | Protected Mailboxes | | --- ## πŸ“¬ Mail Flow Overview ### Daily Volume Trend | Day | Inbound | Outbound | Intra-org | |-----|---------|----------|-----------| | | | | | **Observations:** --- ## πŸ›‘οΈ Threat Composition ### Threat Categories | Category | Count | % of Threats | |----------|-------|-------------| | Phishing | | % | | Spam | | % | | Malware | | % | | High-Confidence Phishing | | β€” | ### Detection Methods | Method | Count | |--------|-------| | | | ### Top Phishing Sender Domains | Domain | Phish Count | Delivered | Recipients Hit | |--------|-------------|-----------|----------------| | | | | | βœ… No phishing sender domains detected. --- ## πŸ“¦ Delivery Disposition ### Initial Delivery Action | Action | Location | Count | |--------|----------|-------| | Delivered | Inbox/folder | | | Blocked | Dropped | | | Blocked | Quarantine | | | Junked | Junk folder | | ### Post-ZAP Threat State | Latest Action | Location | Threat Type | Count | |---------------|----------|-------------|-------| | | | | | **Summary of current threat locations (post-ZAP):** | Current Location | Threat Count | % of Threats | |-----------------|-------------|-------------| | 🟒 Quarantine | | % | | 🟒 Junk folder | | % | | 🟒 Blocked/Dropped/Failed | | % | | 🟒 Deleted items | | % | | πŸ”΄ **Still in Inbox** | **** | **%** | | **Total** | **** | **100%** | > Show the phishing vs spam breakdown for "Still in Inbox": e.g., " phishing ( total threats including spam)" --- ## πŸ” Email Authentication | Protocol | Pass Rate | Pass Count | Fail Count | Other/None | |----------|-----------|------------|------------|------------| | SPF | % | | | | | DMARC | % | | | | | DKIM | % | | | | | CompAuth | % | | | | > **Note:** "Other/None" = emails with no result for that protocol (e.g., no DKIM signature). A low DKIM pass rate with 0 failures means unsigned senders, not spoofing. Compare against DMARC and CompAuth for the complete authentication picture. **Assessment:** - --- ## 🧹 Post-Delivery Remediation (ZAP) | Metric | Value | |--------|-------| | Threat ZAP Actions | (Phish: , Malware: , Spam: ) | | Total Post-Delivery Actions | (includes system events, admin actions) | | ZAP Success Rate | % ( of ) | | Failed Remediations | | > **Reporting guidance:** The Key Metrics "Threat ZAP Actions" row should show **only** the Phish + Malware + Spam ZAP count β€” NOT the TotalActions, which includes system-initiated post-delivery events (message trace updates, delivery location changes). TotalActions is shown separately with a clarifying note. 0:> ⚠️ ** ZAP remediation(s) failed** β€” manual follow-up recommended. Threats may remain in user mailboxes. βœ… All post-delivery remediations completed successfully. --- ## πŸ”— Safe Links Protection | Metric | Value | |--------|-------| | Total Clicks Scanned | | | Clicks Blocked | | | Clicks Allowed | | | Phishing Clicks | | | Click-Through Overrides | | | Distinct URLs Scanned | | | Users Protected | | 0:> πŸ”΄ ** phishing URL click(s) detected** β€” investigate affected users for credential compromise. βœ… No phishing URL click-throughs detected. --- ## πŸ“Ž Attachment Analysis ### Top Attachment Types | File Type | Count | Distinct Files | Threats Detected | |-----------|-------|----------------|------------------| | | | | | 0:> ⚠️ **Malicious attachments detected in file type(s)** β€” verify delivery status and endpoint execution. βœ… No malicious attachments detected in email flow. --- ## 🎯 Targeted Recipients | Recipient Domain | Threat Count | Phish | Spam | Malware | Recipients | |-----------------|-------------|-------|------|---------|------------| | | | | | | | --- ## Email Protection Score Card ``` β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ EMAIL PROTECTION SCORE: /100 β”‚ β”‚ Rating: β”‚ β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€ β”‚ Threat Block Rate [] /20 () β”‚ β”‚ Email Authentication [] /20 () β”‚ β”‚ ZAP Effectiveness [] /20 () β”‚ β”‚ Safe Links Protection[] /20 () β”‚ β”‚ Phishing Delivery [] /20 () β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ ``` --- ## 🚨 MDO Security Incidents ### Incident Summary (Last Days) | Severity | Open | Closed | True Positive | Total | |----------|------|--------|---------------|-------| | πŸ”΄ High | | | | | | 🟠 Medium | | | | | | 🟑 Low | | | | | | πŸ”΅ Informational | | | | | | **Total** | **** | **** | **** | **** | ### Top MDO Incident Types | Alert Name | Severity | Incidents | Open | Closed | True Positives | |------------|----------|-----------|------|--------|----------------| | | | | | | | βœ… No MDO-generated security incidents in the analysis period. --- ## Security Assessment | Factor | Finding | |--------|---------| | **** | | --- ## Recommendations 1. **** β€” 2. ... --- ## Appendix: Query Execution Summary | Query | Description | Records | Time | |-------|-------------|---------|------| | Q1 | Inbound Email Summary | |