logo

Threat Hunting via InternetMessageId (+ KQL Queries)

ID: e60fccda-9071-5f5a-908b-e5c98f71b957

STIX ID: report--e60fccda-9071-5f5a-908b-e5c98f71b957

Feed Name: Detect FYI

Date Published: 2026-04-20

Date Updated: 2026-04-20

Author: Sergio Albea

...
...

This report provides practical threat-hunting guidance and KQL queries for Microsoft EmailEvents that parse InternetMessageId values (notably 'odspnotify' and OneTimePasscode patterns) to detect suspicious email behaviors such as unexpected external sharing, forwarding, or language-agnostic notifications; it presents multiple hypotheses, parsing methods, and example detections to improve email-focused threat detection and investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.