Define email search criteria and request a search on the Microsoft Exchange Online service
As a user with the sn_si.analyst role, define search criteria and submit an email search request based on incident details on a security incident record.
Before you begin
Role required: sn_si.analyst
The figures in this procedure are shown with Tabbed forms selected in System Settings. For more information about selecting and clearing tabbed forms, see the section titled, Display tabbed forms in Configuring the form layout on the ServiceNow Product Documentation website.
Role required: sn_si.analyst
About this task
The status of individual messages that match the search query and the results of the search are reported on the security incident record. If email notifications are enabled, you can view the search results from an email message.
Search criteria may include message sender addresses, recipient addresses, or subject names. The following combinations of message Subject, Sender, and Recipient search parameters are often used for finding phishing-related email messages that may be part of a single phish campaign:- Find all original emails sent by a phishing account: Search by sender.
- Find all original emails for a single phishing campaign: Search by subject and sender.
- Find all emails received for a single phishing campaign (original and forwarded, any sender): Search by subject.
- Find all forwarded emails for a single phishing email from a single user: Search by recipient + subject.
- Find all phishing-related emails sent to a single user: Search by sender + recipient.
The following example shows you how to initiate a search from a ServiceNow AI Platform security incident. A security incident is created based on the original email of a suspected phishing attack in the Microsoft Exchange Online server of your organization. For this example, the search criteria is Sender (From) plus Subject, where From is phisher@cbazyx.com, and the Subject is log in to your account.
Results for searches on subjects are returned when the search finds text strings that contain key words that match the entered search criteria. In this example, the subject is log in to your account. Use the AND operator to separate the From and Subject search conditions to return results for all the email messages that contain these given search criteria. The following steps describe how to set up a search that finds only emails that contain subject line text sent by a specific phishing account.