KQL - URL Exposure, Click, and Endpoint Activity Correlator
Correlates email delivery, URL click telemetry, endpoint network connections, and process execution evidence for one or more suspicious URLs or domains. This query helps analysts identify who received an email containing a target URL, who clicked it, whether the URL was observed on managed endpoints, which devices were involved, and what processes initiated related network or command-line activity. It is useful for phishing investigations, malicious URL exposure reviews, post-delivery impact checks, campaign scoping, and confirming whether a user interaction led to endpoint activity. The query uses Microsoft Defender XDR advanced hunting tables including EmailUrlInfo, EmailEvents, UrlClickEvents, DeviceNetworkEvents, and DeviceProcessEvents. Microsoft documents UrlClickEvents as containing Safe Links click information from email messages, Teams, and Office apps, populated by Defender for Office 365.
Microsoft Sentinel (KQL)

