You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-office-365/threat-explorer-real-time-detections-about.md
+22-15Lines changed: 22 additions & 15 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ ms.author: chrisda
7
7
manager: bagol
8
8
audience: ITPro
9
9
ms.topic: concept-article
10
-
ms.date: 08/28/2025
10
+
ms.date: 09/08/2025
11
11
ms.localizationpriority: medium
12
12
ms.collection:
13
13
- m365-security
@@ -203,7 +203,7 @@ The filterable properties that are available in the **Delivery action** box in t
203
203
|**Advanced**||
204
204
|Internet Message ID|Text. Separate multiple values by commas. <br/><br/> Available in the **Message-ID** header field in the message header. An example value is `<[email protected]>` (note the angle brackets).|
205
205
|Network message ID|Text. Separate multiple values by commas. <br/><br/> A GUID value that's available in the **X-MS-Exchange-Organization-Network-Message-Id** header field in the message header.|
206
-
|Sender IP|Text. Separate multiple values by commas.|
206
+
|Sender IP²|Text. Separate multiple values by commas.|
207
207
|Attachment SHA256|Text. Separate multiple values by commas.|
208
208
|Cluster ID|Text. Separate multiple values by commas.|
209
209
|Alert ID|Text. Separate multiple values by commas.|
@@ -212,10 +212,10 @@ The filterable properties that are available in the **Delivery action** box in t
212
212
|ZAP URL signal|Text. Separate multiple values by commas.|
213
213
|**Urls**||
214
214
|URL Count|Integer. Separate multiple values by commas.|
215
-
|URL domain²|Text. Separate multiple values by commas.|
216
-
|URL domain and path²|Text. Separate multiple values by commas.|
217
-
|URL²|Text. Separate multiple values by commas.|
218
-
|URL path²|Text. Separate multiple values by commas.|
215
+
|URL domain³|Text. Separate multiple values by commas.|
216
+
|URL domain and path³|Text. Separate multiple values by commas.|
217
+
|URL³|Text. Separate multiple values by commas.|
218
+
|URL path³|Text. Separate multiple values by commas.|
219
219
|URL source|Select one or more values: <ul><li>**Attachments**</li><li>**Cloud attachment**</li><li>**Email body**</li><li>**Email header**</li><li>**QR Code**</li><li>**Subject**</li><li>**Unknown**</li></ul>|
220
220
|Click verdict|Select one or more values: <ul><li>**Allowed**: The user was allowed to open the URL.</li><li>**Block overridden**: The user was blocked from directly opening the URL, but they overrode the block to open the URL.</li><li>**Blocked**: The user was blocked from opening the URL.</li><li>**Error**: The user was presented with the error page, or an error occurred in capturing the verdict.</li><li>**Failure**: An unknown exception occurred while capturing the verdict. The user might have opened the URL.</li><li>**None**: Unable to capture the verdict for the URL. The user might have opened the URL.</li><li>**Pending verdict**: The user was presented with the detonation pending page.</li><li>**Pending verdict bypassed**: The user was presented with the detonation page, but they overrode the message to open the URL.</li></ul>|
221
221
|URL Threat|Select one or more values: <ul><li>**Malware**</li><li>**Phish**</li><li>**Spam**</li></ul>|
@@ -232,19 +232,26 @@ The filterable properties that are available in the **Delivery action** box in t
232
232
|Composite|Select one or more values: <ul><li>**Fail**</li><li>**None**</li><li>**Pass**</li><li>**Soft pass**</li></ul>|
233
233
234
234
> [!TIP]
235
-
> ¹ **Latest delivery location** doesn't include end-user actions on messages. For example, if the user deleted the message or moved the message to an archive or PST file.
236
235
>
237
-
> There are scenarios where **Original delivery location**/**Latest delivery location**and/or **Delivery action** have the value **Unknown**. For example:
236
+
> - ¹ **Latest delivery location**doesn't include end-user actions on messages. For example, if the user deleted the message or moved the message to an archive or PST file.
238
237
>
239
-
> - The message was delivered (**Delivery action** is **Delivered**), but an Inbox rule moved the message to a default folder other than the Inbox or Junk Email folder (for example, the Draft or Archive folder).
240
-
> - ZAP attempted to move the message after delivery, but the message wasn't found (for example, the user moved or deleted the message).
238
+
> There are scenarios where **Original delivery location**/**Latest delivery location** and/or **Delivery action** have the value **Unknown**. For example:
241
239
>
242
-
> ² By default, a URL search maps to `http`, unless another value is explicitly specified. For example:
240
+
> - The message was delivered (**Delivery action** is **Delivered**), but an Inbox rule moved the message to a default folder other than the Inbox or Junk Email folder (for example, the Draft or Archive folder).
241
+
> - ZAP attempted to move the message after delivery, but the message wasn't found (for example, the user moved or deleted the message).
243
242
>
244
-
> - Searching with and without the `http://` prefix in **URL**, **URL Domain**, and **URL Domain and Path** should show the same results.
245
-
> - Search for the `https://` prefix in **URL**. When no value is specified, the `http://` prefix is assumed.
246
-
> -`/` at the beginning and end of the **URL path**, **URL Domain**, **URL domain and path** fields is ignored.
247
-
> -`/` at the end of the **URL** field is ignored.
243
+
> - ² **Sender IP** values are sometimes logged as empty or 0.0.0.0 in the following scenarios:
244
+
> - Automatic replies.
245
+
> - Undelivered email where delivery has failed.
246
+
> - Email where the sender IP address is Microsoft internal. For example, system generated notifications, alerts, or forwarded messages delivered from Microsoft IP addresses.
247
+
>
248
+
> IP addresses in these scenarios might be visisble in Exchange message trace.
249
+
>
250
+
> - ³ By default, a URL search maps to `http`, unless another value is explicitly specified. For example:
251
+
> - Searching with and without the `http://` prefix in **URL**, **URL Domain**, and **URL Domain and Path** should show the same results.
252
+
> - Search for the `https://` prefix in **URL**. When no value is specified, the `http://` prefix is assumed.
253
+
> -`/` at the beginning and end of the **URL path**, **URL Domain**, **URL domain and path** fields is ignored.
254
+
> -`/` at the end of the **URL** field is ignored.
248
255
249
256
### Pivots for the chart in the All email view in Threat Explorer
0 commit comments