Defender-MessageUrlInfo

ActionTypeTitleSampleRule
anyTeams message URL observedNY

any: Teams message URL observed

#
Table
MessageUrlInfo

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Url1 detection ruleKusto

Detection Patterns #

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
ThreadType (kusto rule field)eqchat1 rulekusto

References #