Microsoft 365 to Provide Detonation Details About Malicious Email Content

Stu Sjouwerman | Jun 19, 2020

iStock-1167560531In a step towards educating customers on why attachments and URLs are deemed “malicious”, Microsoft’s is set to augment its Advanced Threat Protection product in July.

There are lots of reasons why a security solution comes to a “malicious verdict” when it comes to email content. It could be the URL link in the email points to a site that’s been compromised. Or perhaps it’s that the attachment, when detonated, attempted to install software. In some cases, IT organizations never know – and can’t be better protected through experiential knowledge.

But a new update to Microsoft’s Advanced Threat Protection product will provide customers with details on any malicious behaviors the solution finds when examining and detonating email content.

According to the Microsoft 365 Roadmap entry:

We’re working to reveal more of the details that led to a malicious verdict when URLs or files are detonated in Office 365 ATP. In addition to the detonation chain (the series of detonations that were necessary to reach a verdict for this entity), we’ll also share a detonation summary, with details such as detonation time range, verdict of the file or URL, related entities (other entities called or used during the detonation), screenshots, and more.

This is a huge step in not only demonstrating the effectiveness of Microsoft’s solution, but this also allows organizations to better understand what tactics are being used and how their other security solutions can be used to protect the organization.

This spirit of educating the “why” behind malicious is what Security Awareness Training is all about; by teaching IT and users what tactics are being used, everyone’s understanding of attacks and the need for vigilance is elevated, only helping to improve the organization’s security stance.

Discover Your Organization’s Exposed Email Attack Surface

Cybercriminals constantly scan the deep web and thousands of breach databases to find exposed employee identities, credentials, and passwords to launch targeted social engineering attacks. Run our free Email Exposure Check Pro (EEC) to safely uncover your at-risk users and see what your organizational structure looks like to an attacker before they exploit it.

Get Your Free Email Exposure Report

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.