@nathanmcnulty Is there a way in KQL to find macro enabled documents that have the MOTW flag set?
@justaq I'll have to write it later when I'm at a computer, but yes we can. It'll be using file extension (docm, xlsm, etc.) with, I think, RemoteUrl.
If you can, check the schema on DeviceFileEvents. Again, all from memory here, so I can check later when at a computer ;)