The User Reported The Email - But It Was Already Gone
The user did the right thing.
They reported a suspicious email to IT.
But when the security team opened the mailbox, the message was no longer there. Agent Foskett wanted to know whether the email had been deleted, quarantined, moved or silently remediated by Microsoft 365.
Briefing summary
A suspicious email was reported, but by the time IT searched the inbox, the message had disappeared. The investigation focused on Defender XDR telemetry, delivery location, post-delivery actions and whether Microsoft had already remediated the message.
The report came in late
The first investigation question
The KQL investigation
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
EmailEvents | where Timestamp > ago(30d) | where RecipientEmailAddress == "user@contoso.com" | where Subject contains "invoice" or Subject contains "payment" | project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, ThreatTypes, DeliveryAction, DeliveryLocation
What the logs can explain
Was it a wider campaign?
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
EmailEvents | where Timestamp > ago(30d) | where Subject contains "invoice" or Subject contains "payment" | summarize TotalMessages = count(), Recipients = dcount(RecipientEmailAddress), FirstSeen = min(Timestamp), LastSeen = max(Timestamp) by SenderFromAddress, SenderIPv4
Checking user impact
URL click investigation
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
UrlClickEvents | where Timestamp > ago(7d) | where AccountUpn == "user@contoso.com" | project Timestamp, AccountUpn, Url, ActionType, Workload
Why the message disappeared
Agent Foskett moment
Questions every analyst should ask
Related investigations
Final thought
The user reported the email. The mailbox no longer showed it. The logs explained why. Explore related investigations including DeliveryLocation investigations, UrlClickEvents, and post-delivery click analysis.
Develop IT. Protect IT. GEMXIT PTY LTD | GEMXIT UK LTD