Skip to main content
Question

Create cases in SecOps based on received emails

  • May 11, 2026
  • 2 replies
  • 21 views

0xM4XDF1R
Forum|alt.badge.img+3

Hi!

 

Is it possible to create cases in SecOps based on emails received in O365?

Any experiences?

2 replies

cmorris
Staff
Forum|alt.badge.img+12
  • Staff
  • May 11, 2026

Yes, use the connector from the Microsoft Graph Mail  integration - https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/microsoft-graph-mail#microsoft_graph_mail_connector. I have seen a few uses of the connector to monitor and ingest alerts from mailboxes used for forwarding security incidents and phishing emails.


0xM4XDF1R
Forum|alt.badge.img+3
  • Author
  • New Member
  • May 12, 2026

Yes, use the connector from the Microsoft Graph Mail  integration - https://docs.cloud.google.com/chronicle/docs/soar/marketplace-integrations/microsoft-graph-mail#microsoft_graph_mail_connector. I have seen a few uses of the connector to monitor and ingest alerts from mailboxes used for forwarding security incidents and phishing emails.

Seems to work fine! But are you able to append additional replys / email thread to the same case?