Top Internal Users Auto-forwarding Email Externally (Mailbox Rule and SMTP)
Description
This query lists the top internal users automatically forwarding email to external addresses, by forwarding type, using the EmailEvents table.
Query · kql
EmailEvents
| where Timestamp > ago(30d)
| where EmailDirection == "Outbound" and isnotempty(ForwardingInformation)
| extend Key = strcat(NetworkMessageId, '-', RecipientEmailAddress)
| summarize arg_max(Timestamp, *) by Key
| extend FwdInfo = parse_json(ForwardingInformation)
| extend ForwardingType = tostring(FwdInfo.ForwardingType),
ForwardingUser = tostring(FwdInfo.ForwardingUser),
RecipientDomain = tostring(split(RecipientEmailAddress, '@')[1])
| where isnotempty(ForwardingUser)
| summarize ForwardedMessages = count(),
ExternalRecipients = dcount(RecipientEmailAddress),
ExternalDomains = dcount(RecipientDomain)
by ForwardingUser, ForwardingType
| top 20 by ForwardedMessages