Skip to content

trisdev75/Microsoft-Defender-for-M365

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

14 Commits
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ Microsoft Defender for Office 365 (Exchange Online)

This repository will centralize articles and real-world examples related to Microsoft Defender for Office 365, with a specific focus on Exchange Online and email protection.

πŸ“˜ Context

Microsoft Defender for Office 365 offers multiple layers of protection to detect, investigate, and respond to threats targeting Exchange Online.
This repository aims to share use cases, hunting queries, investigation scenarios, and technical notes based on real-life experience in production environments.

🚧 Topics to be covered (articles coming soon)

  • 🎯 Targeted attack protection (phishing, spoofing, malware)
  • 🧠 Threat investigation using Microsoft 365 Defender and Email Entity
  • πŸ“¬ Message headers analysis (SPF, DKIM, DMARC)
  • πŸ” Advanced Hunting (KQL queries focused on email events)
  • πŸ—‚οΈ Email Quarantine & Threat Explorer
  • πŸ” Auto-remediation and manual response workflows
  • πŸ› οΈ PowerShell scripts for reporting or investigation

πŸ“Œ Notes

All content in this repository is shared for educational purposes and based on hands-on experience.
Articles will be added progressively as they are written and validated.

πŸ“„ License

This repository is published under the CC BY 4.0 license.

About

πŸ›‘οΈ Scripts and articles about Microsoft Defender M365

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors