Threat Hunting via InternetMessageId (+ KQL Queries)
ID: e60fccda-9071-5f5a-908b-e5c98f71b957
STIX ID: report--e60fccda-9071-5f5a-908b-e5c98f71b957
Feed Name: Detect FYI
This report provides practical threat-hunting guidance and KQL queries for Microsoft EmailEvents that parse InternetMessageId values (notably 'odspnotify' and OneTimePasscode patterns) to detect suspicious email behaviors such as unexpected external sharing, forwarding, or language-agnostic notifications; it presents multiple hypotheses, parsing methods, and example detections to improve email-focused threat detection and investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
