Query Details

Delivered Mail Carrying Exfiltration Style Urls

Query

let lookback = 30d;
EmailEvents
| where Timestamp > ago(lookback)
| where DeliveryAction == "Delivered"
| join kind=inner (
    EmailUrlInfo
    | where Timestamp > ago(lookback)
) on NetworkMessageId
| where Url matches regex @"(?i)([?&](data|q|payload|d)=[A-Za-z0-9+/]{24,}={0,2}|/(collect|exfil|log)\b)"
| project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, Url, DeliveryLocation
| sort by Timestamp desc

About this query

Delivered mail carrying exfiltration-style URLs

Description

This query joins delivered messages to their URLs and flags long, encoded-looking query parameters or collector-style paths, the shape an AI assistant would be instructed to call.

  • Note on field values: the exact DetectionMethods string can vary by tenant and evolve over time (in my data it appeared as {"Phish":["Prompt Injection..."]}). Confirm the literal in your own EmailEvents before operationalizing an alert, and treat this query's regex as a starting heuristic to tune against your legitimate URL patterns to keep false positives down. Always consider reviewing [https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-emailevents-table](Advanced Hunting schema).

Microsoft Defender XDR

Versioning

VersionDateComments
1.008/10/2026Initial publish

Explanation

This query is designed to identify potentially malicious emails that have been delivered and contain URLs indicative of data exfiltration attempts. Here's a simplified breakdown of what the query does:

  1. Time Frame: It looks at email events from the past 30 days.

  2. Filter for Delivered Emails: It focuses on emails that were successfully delivered.

  3. Join with URL Information: It combines the email data with URL information from the same emails, using a common identifier (NetworkMessageId).

  4. Identify Suspicious URLs: It searches for URLs within these emails that have:

    • Long, encoded-looking query parameters (e.g., parameters like data, q, payload, or d followed by a long string of characters).
    • Paths that suggest data collection or exfiltration (e.g., paths containing collect, exfil, or log).
  5. Output: It lists the timestamp, sender's address, recipient's email address, email subject, the suspicious URL, and where the email was delivered.

  6. Sort Order: The results are sorted by the timestamp in descending order, showing the most recent events first.

The query is a starting point and should be adjusted to fit the specific URL patterns and detection methods relevant to your organization to minimize false positives.