KQL - Email Message Deep Inspection
Provides a consolidated view of email metadata, delivery outcomes, attachments, embedded URLs, sender infrastructure, and security verdicts for inbound and outbound email investigations. The query enriches email events with attachment and URL data, allowing analysts to quickly assess: Sender and recipient information Delivery actions Phishing and spam verdicts URLs contained within messages Attached files and hashes Threat classifications Sender IP infrastructure This query is useful for phishing investigations, malware delivery analysis, threat hunting, and message trace reviews.
Microsoft Sentinel (KQL)

