Skip to content

Commit 9767517

Browse files
authored
Merge pull request #4960 from ajaj-shaikh/patch-13
Update threat-explorer-real-time-detections-about.md
2 parents 07d9de2 + b7c389a commit 9767517

File tree

1 file changed

+22
-15
lines changed

1 file changed

+22
-15
lines changed

defender-office-365/threat-explorer-real-time-detections-about.md

Lines changed: 22 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ ms.author: chrisda
77
manager: bagol
88
audience: ITPro
99
ms.topic: concept-article
10-
ms.date: 08/28/2025
10+
ms.date: 09/08/2025
1111
ms.localizationpriority: medium
1212
ms.collection:
1313
- m365-security
@@ -203,7 +203,7 @@ The filterable properties that are available in the **Delivery action** box in t
203203
|**Advanced**||
204204
|Internet Message ID|Text. Separate multiple values by commas. <br/><br/> Available in the **Message-ID** header field in the message header. An example value is `<[email protected]>` (note the angle brackets).|
205205
|Network message ID|Text. Separate multiple values by commas. <br/><br/> A GUID value that's available in the **X-MS-Exchange-Organization-Network-Message-Id** header field in the message header.|
206-
|Sender IP|Text. Separate multiple values by commas.|
206+
|Sender IP²|Text. Separate multiple values by commas.|
207207
|Attachment SHA256|Text. Separate multiple values by commas.|
208208
|Cluster ID|Text. Separate multiple values by commas.|
209209
|Alert ID|Text. Separate multiple values by commas.|
@@ -212,10 +212,10 @@ The filterable properties that are available in the **Delivery action** box in t
212212
|ZAP URL signal|Text. Separate multiple values by commas.|
213213
|**Urls**||
214214
|URL Count|Integer. Separate multiple values by commas.|
215-
|URL domain²|Text. Separate multiple values by commas.|
216-
|URL domain and path²|Text. Separate multiple values by commas.|
217-
|URL²|Text. Separate multiple values by commas.|
218-
|URL path²|Text. Separate multiple values by commas.|
215+
|URL domain³|Text. Separate multiple values by commas.|
216+
|URL domain and path³|Text. Separate multiple values by commas.|
217+
|URL³|Text. Separate multiple values by commas.|
218+
|URL path³|Text. Separate multiple values by commas.|
219219
|URL source|Select one or more values: <ul><li>**Attachments**</li><li>**Cloud attachment**</li><li>**Email body**</li><li>**Email header**</li><li>**QR Code**</li><li>**Subject**</li><li>**Unknown**</li></ul>|
220220
|Click verdict|Select one or more values: <ul><li>**Allowed**: The user was allowed to open the URL.</li><li>**Block overridden**: The user was blocked from directly opening the URL, but they overrode the block to open the URL.</li><li>**Blocked**: The user was blocked from opening the URL.</li><li>**Error**: The user was presented with the error page, or an error occurred in capturing the verdict.</li><li>**Failure**: An unknown exception occurred while capturing the verdict. The user might have opened the URL.</li><li>**None**: Unable to capture the verdict for the URL. The user might have opened the URL.</li><li>**Pending verdict**: The user was presented with the detonation pending page.</li><li>**Pending verdict bypassed**: The user was presented with the detonation page, but they overrode the message to open the URL.</li></ul>|
221221
|URL Threat|Select one or more values: <ul><li>**Malware**</li><li>**Phish**</li><li>**Spam**</li></ul>|
@@ -232,19 +232,26 @@ The filterable properties that are available in the **Delivery action** box in t
232232
|Composite|Select one or more values: <ul><li>**Fail**</li><li>**None**</li><li>**Pass**</li><li>**Soft pass**</li></ul>|
233233

234234
> [!TIP]
235-
> ¹ **Latest delivery location** doesn't include end-user actions on messages. For example, if the user deleted the message or moved the message to an archive or PST file.
236235
>
237-
> There are scenarios where **Original delivery location**/**Latest delivery location** and/or **Delivery action** have the value **Unknown**. For example:
236+
> - ¹ **Latest delivery location** doesn't include end-user actions on messages. For example, if the user deleted the message or moved the message to an archive or PST file.
238237
>
239-
> - The message was delivered (**Delivery action** is **Delivered**), but an Inbox rule moved the message to a default folder other than the Inbox or Junk Email folder (for example, the Draft or Archive folder).
240-
> - ZAP attempted to move the message after delivery, but the message wasn't found (for example, the user moved or deleted the message).
238+
> There are scenarios where **Original delivery location**/**Latest delivery location** and/or **Delivery action** have the value **Unknown**. For example:
241239
>
242-
> ² By default, a URL search maps to `http`, unless another value is explicitly specified. For example:
240+
> - The message was delivered (**Delivery action** is **Delivered**), but an Inbox rule moved the message to a default folder other than the Inbox or Junk Email folder (for example, the Draft or Archive folder).
241+
> - ZAP attempted to move the message after delivery, but the message wasn't found (for example, the user moved or deleted the message).
243242
>
244-
> - Searching with and without the `http://` prefix in **URL**, **URL Domain**, and **URL Domain and Path** should show the same results.
245-
> - Search for the `https://` prefix in **URL**. When no value is specified, the `http://` prefix is assumed.
246-
> - `/` at the beginning and end of the **URL path**, **URL Domain**, **URL domain and path** fields is ignored.
247-
> - `/` at the end of the **URL** field is ignored.
243+
> - ² **Sender IP** values are sometimes logged as empty or 0.0.0.0 in the following scenarios:
244+
> - Automatic replies.
245+
> - Undelivered email where delivery has failed.
246+
> - Email where the sender IP address is Microsoft internal. For example, system generated notifications, alerts, or forwarded messages delivered from Microsoft IP addresses.
247+
>
248+
> IP addresses in these scenarios might be visisble in Exchange message trace.
249+
>
250+
> - ³ By default, a URL search maps to `http`, unless another value is explicitly specified. For example:
251+
> - Searching with and without the `http://` prefix in **URL**, **URL Domain**, and **URL Domain and Path** should show the same results.
252+
> - Search for the `https://` prefix in **URL**. When no value is specified, the `http://` prefix is assumed.
253+
> - `/` at the beginning and end of the **URL path**, **URL Domain**, **URL domain and path** fields is ignored.
254+
> - `/` at the end of the **URL** field is ignored.
248255
249256
### Pivots for the chart in the All email view in Threat Explorer
250257

0 commit comments

Comments
 (0)