The Sender Wasn't Really The Sender
The display name looked familiar.
The visible sender looked trusted.
But the envelope sender, return path and authentication details told a different story.
Briefing summary
An email appeared to come from a trusted sender, but Microsoft Defender XDR showed the sender identity did not align. Agent Foskett compared SenderFromAddress, SenderMailFromAddress, ReturnPath, SpoofedDomain and authentication results to determine who really sent the message.
What happened
The fields that changed the investigation
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
EmailEvents | where Timestamp > ago(7d) | project Timestamp, RecipientEmailAddress, SenderFromAddress, SenderMailFromAddress, SenderDisplayName, ReturnPath, SpoofedDomain, AuthenticationDetails, EmailDirection, DeliveryAction
Agent Foskett moment
What most environments miss
How defenders can investigate it
Related investigations
Final thought
The display name looked trusted, but EmailEvents showed the visible sender, envelope sender and return path were not aligned. Explore related investigations including SpoofedDomain In EmailEvents, EmailEvents KQL Guide, and AuthenticationDetails Explained.
Develop IT. Protect IT. GEMXIT PTY LTD | GEMXIT UK LTD