EmailEvents
| where SenderMailFromDomain == RecipientDomain
| where isempty(Connectors)
| where DeliveryAction !in ("Junked", "Blocked")
| extend AuthenticationDetails = parse_json(AuthenticationDetails)
| where AuthenticationDetails.DMARC == "fail"
EmailEvents
| where SenderMailFromDomain == RecipientDomain
| where isempty(Connectors)
| where DeliveryAction !in ("Junked", "Blocked")
| extend AuthenticationDetails = parse_json(AuthenticationDetails)
| where AuthenticationDetails.DMARC == "fail"
techcommunity.microsoft.com/blog/exchang...
#MSExchange #ExchangeOnline #DirectSend #PublicPreview
techcommunity.microsoft.com/blog/exchang...
#MSExchange #ExchangeOnline #DirectSend #PublicPreview
#Cybersecurity #Cybersicherheit #DirectSend #EMailSecurity #EMailSicherheit #ExchangeOnline KnowBe4 #KnowBe4ThreatLab #Microsoft365 #SecurityAwareness
netzpalaver.de/2026/...
#Cybersecurity #Cybersicherheit #DirectSend #EMailSecurity #EMailSicherheit #ExchangeOnline KnowBe4 #KnowBe4ThreatLab #Microsoft365 #SecurityAwareness
netzpalaver.de/2026/...
gbhackers.com/hackers-expl...
#Infosec #Security #Cybersecurity #CeptBiro #Exploit #Microsoft365 #DirectSend #Evade #Filters #StealData
gbhackers.com/hackers-expl...
#Infosec #Security #Cybersecurity #CeptBiro #Exploit #Microsoft365 #DirectSend #Evade #Filters #StealData
https://blog.talosintelligence.com/reducing-abuse-of-microsoft-365-exchange-onlines-direct-send/
https://blog.talosintelligence.com/reducing-abuse-of-microsoft-365-exchange-onlines-direct-send/