Microsoft Defender for Endpoint KQL - Action Types

Vasilije Djurovic 66 Reputation points
2024-01-10T11:10:57.47+00:00

Hello Everyone,

I was wondering if someone can explain me a dieffrence betwen Action types in Microsoft Defender for Endpoint when hunting events via Advanced Hunting.

We wanted to have a deeper visibility on how many users have downloaded attachment from Outlook that contains malicious test document since we preformed phishing test in our company.

When i try to look for the events in advanced hunting query i get "FileCreated" and "FileModified" action type but it typically refers to temp data folder of Outlook, not Downloads folder. How can i be certain that users maybe opened files via web browser/ as temp file on machine, these file events are unclear to me, can someone please explain little better.

Best Regards.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
374 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 45,986 Reputation points Microsoft Vendor
    2024-01-11T01:50:16.2733333+00:00

    @Vasilije Djurovic, Thanks for posting in Q&A. From your description, it seems the question is related to Microsoft Defender for endpoint which we are not familiar. You can contact the support in the following link to get help:

    https://video2.skills-academy.com/en-us/microsoft-365/security/defender-endpoint/contact-support?view=o365-worldwide

    Thanks for your understanding.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments