Search

70613 – Microsoft Defender for Office 365: Hunting for Impersonated domains and users (archived)

cloudscout.one Icon

*For this entry exists the more relevant or more recent entry MC241580

check before: 2021-02-28

Product:

Advanced Threat Protection - Office 365, Defender, Defender ATP, Defender for Office 365, Microsoft Defender for Office 365

Platform:

Online, Web, World tenant

Status:

Launched

Change type:

Admin impact, New feature

Links:

MC241580

Details:

Threat Explorer (P2) and Real-time detections (P1) are powerful near real-time tools to help Security Operations teams investigate and respond to threats. Today we provide filters for Detection Technology with User impersonation or Domain impersonation which show all Phish emails caught by our impersonation detection. We are adding new filters called Impersonated user and Impersonated domain to enable Security Operations teams to explicitly hunt for specific users or domains within their organization that are targets of impersonation attacks. This additional information related to Impersonated domain(s) and Impersonated user(s) will surface in existing Impersonation insight pages and our new Email Entity page.

Change Category:
XXXXXXX ...

Scope:
XXXXXXX ...

Release Phase:
General Availability

Created:
2021-02-02

updated:
2021-10-14

the free basic plan is required to see all details. Sign up here


A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.


Last updated 11 months ago

Share to MS Teams

Login to your account

Welcome Back, We Missed You!