#DirectSend
KQL to review #DirectSend abuse

EmailEvents​
| where SenderMailFromDomain == RecipientDomain​
| where isempty(Connectors)​
| where DeliveryAction !in ("Junked", "Blocked")​
| extend AuthenticationDetails = parse_json(AuthenticationDetails)​
| where AuthenticationDetails.DMARC == "fail"​
August 5, 2025 at 11:47 PM
September 16, 2026 at 12:43 PM
#MSXFAQ Exchange DirectSend/RejectDirectSend www.msxfaq.de/cloud/exchan... - Es ist kein #Expoit!. aber es gibt viel Verwirrung um eine neue Einstellung in #ExchangeOnline. So steuern sie wer Mails von ihrer eigenen Domain direkt an ihren Tenant senden kann, um Phishing zu verhindern.
August 7, 2025 at 8:06 AM
A teammate and I wrote a quick overview on the Microsoft #directsend issue that bypasses email authentication and anti-spoofing:
https://blog.talosintelligence.com/reducing-abuse-of-microsoft-365-exchange-onlines-direct-send/
Reducing abuse of Microsoft 365 Exchange Online’s Direct Send
Cisco Talos has observed increased activity by malicious actors leveraging Direct Send as part of phishing campaigns. Here's how to strengthen your defenses.
blog.talosintelligence.com
October 21, 2025 at 4:08 PM
EXO ETR to quarantine DirectSend emails (sample, use with care/caution/and lighter handed actions than the picture!
August 5, 2025 at 11:49 PM