Defender-MessageUrlInfo
| ActionType | Title | Sample | Rule |
|---|---|---|---|
| any | Teams message URL observed | N | Y |
any: Teams message URL observed
#Detection Fields #
Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.
| Name | Rules | Vendors |
|---|---|---|
Url | 1 detection rule | Kusto |
Detection Patterns #
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
ThreadType (kusto rule field) | eq | chat | 1 rule | kusto |