Microsoft 365 Defender - Threat Hunting Generic

This playbook retrieves email data based on the `URLDomain`, `SHA256`, `IPAddress`. and `MessageID` inputs. The output is a unified object with all of the retrieved emails based on the following sub-playbooks outputs: - **Microsoft 365 Defender - Get Email URL clicks**: Retrieves data based on URL click events. - **Microsoft 365 Defender - Emails Indicators Hunt**: Retrieves data based on several different email events. Read the playbook's descriptions in order to get the full details.

Pack
Microsoft365Defender
Tasks
4

Inputs

Outputs