Use the Office 365 Malicious File Detected playbook
Freigeben Version: Australia
Aktualisiert 12. März 2026
2 Minuten Lesedauer
Use this playbook to investigate malicious files detected in Office 365. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Office 365 Malicious File Detected
playbook.
Vorbereitungen
Role required:
sn_si.admin
flow_designer
Prozedur
When the playbook is triggered and starts executing, in Action 1, you need to extract the malicious file from the Office 365 console.
In Action 2, you need to analyze whether the file or hash has been added as an observable in the Threat Intel Platform.
In Action 3, you need to investigate the file name and path to determine whether it is a known or non-malicious file/application.