Try in Splunk SOAR


Accepts message ID that needs to be evicted from provided email mailbox in Microsoft Office365. Generates an observable output based on the status of message eviction.

  • Type: Response
  • Product: Splunk SOAR
  • Apps: MS Graph for Office 365
  • Last Updated: 2024-01-21
  • Author: Lou Stella, Splunk
  • ID: 5299d6dd-e9c4-4bfd-b031-928acd1ff816
  • Use-cases:
    • Phishing

Associated Detections

How To Implement

This input playbook requires the MS Graph for Office 365 connector to be configured.


ID Technique Definition Category
D3-ER Email Removal The file removal technique deletes malicious artifacts or programs from a computer system. File Eviction

Explore Playbook


Required field


source | version: 1