{"id":"3569aefd-e535-4391-8c18-24bd01a21eaf","title":"Suspicious Email Delivered In Microsoft 365","description":"Detects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder.\nIt might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.\n","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2026-01-27","modified":"","tags":["attack.initial-access","attack.t1566.001","attack.t1566.002"],"technique_ids":["T1566.001","T1566.002"],"logsource":{"service":"audit","product":"m365"},"falsepositives":["Unlikely"],"references":["https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about","https://research.splunk.com/cloud/605cc93a-70e4-4ee3-9a3d-1a62e8c9b6c2/","https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules/blob/e7250648cb16d4a497ae8737943bf010ea96d2e6/Defender%20For%20Cloud%20Apps/MaliciousEmailDeliveredInMailbox.md"],"source_path":"rules/cloud/m365/audit/microsoft365_suspicious_email_delivered.yml","source_sha256":"808b309382febc4e635c011d7a4a1d85406a97c022b75df7209bb5946382c1cc","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/cloud/m365/audit/microsoft365_suspicious_email_delivered.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Suspicious Email Delivered In Microsoft 365\nid: 3569aefd-e535-4391-8c18-24bd01a21eaf\nstatus: experimental\ndescription: |\n    Detects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder.\n    It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.\nreferences:\n    - https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about\n    - https://research.splunk.com/cloud/605cc93a-70e4-4ee3-9a3d-1a62e8c9b6c2/\n    - https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules/blob/e7250648cb16d4a497ae8737943bf010ea96d2e6/Defender%20For%20Cloud%20Apps/MaliciousEmailDeliveredInMailbox.md\nauthor: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)\ndate: 2026-01-27\ntags:\n    - attack.initial-access\n    - attack.t1566.001\n    - attack.t1566.002\nlogsource:\n    service: audit\n    product: m365\ndetection:\n    selection:\n        Workload: 'ThreatIntelligence'\n        Operation: 'TIMailData'\n        Directionality: 'Inbound'\n    filter_main_blocked:\n        DeliveryAction: 'Blocked'\n    condition: selection and not 1 of filter_main_*\nfalsepositives:\n    - Unlikely\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1566.001","id":"T1566.001","name":"Spearphishing Attachment","page":"techniques/enterprise/T1566.001/"},{"key":"enterprise/T1566.002","id":"T1566.002","name":"Spearphishing Link","page":"techniques/enterprise/T1566.002/"}],"data_path":"data/detection-rules/3569aefd-e535-4391-8c18-24bd01a21eaf.json","kind":"sigma"}
