Follow the File Hash: Hunting for Sensitive Files Leaving Your Organization with Defender Advanced…
ID: 00b3d904-fe12-5bd0-bd69-641161e97cfd
STIX ID: report--00b3d904-fe12-5bd0-bd69-641161e97cfd
Feed Name: Detect FYI
This article explains how to use KQL queries to correlate endpoint telemetry (MDE DeviceFileEvents) and email telemetry (MDO EmailAttachmentInfo) via SHA256 hashes to detect when sensitivity‑labeled files are sent to external recipients. It provides example queries, notes on customizing sensitivity labels and organization domains, and mentions Microsoft Purview Insider Risk Management as an additional telemetry source for detecting risky email exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
