Automatic External Email Forwarding Overview by Type (Mailbox Rule and SMTP)


Description

This query summarises automatic external email forwarding across the tenant by forwarding type (mailbox rule versus SMTP forwarding), using the EmailEvents table.

Query · kql

EmailEvents
| where Timestamp > ago(30d)
| where EmailDirection == "Outbound" and isnotempty(ForwardingInformation)
| extend Key = strcat(NetworkMessageId, '-', RecipientEmailAddress)
| summarize arg_max(Timestamp, *) by Key
| extend FwdInfo = parse_json(ForwardingInformation)
| extend ForwardingType = tostring(FwdInfo.ForwardingType),
         ForwardingUser = tostring(FwdInfo.ForwardingUser),
         RecipientDomain = tostring(split(RecipientEmailAddress, '@')[1])
| summarize ForwardedMessages = count(),
            ForwardingUsers = dcount(ForwardingUser),
            ExternalRecipients = dcount(RecipientEmailAddress),
            ExternalDomains = dcount(RecipientDomain)
    by ForwardingType
| sort by ForwardedMessages desc
Raw source Automatic External Email Forwarding Overview by Type (Mailbox Rule and SMTP) · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: d05eb85d-16e6-4bb9-a669-78da03ec6417
name: Automatic External Email Forwarding Overview by Type (Mailbox Rule and SMTP)
description: |
  This query summarises automatic external email forwarding across the tenant by forwarding type (mailbox rule versus SMTP forwarding), using the EmailEvents table.
description-detailed: |
  A compromised mailbox is often configured to automatically forward mail to an external address to exfiltrate data. This query summarises outbound messages auto-forwarded to external recipients, split by forwarding type (MbxRule and SmtpForwarding), with the number of forwarding users, external recipients and external domains for each type. Use it to size the auto-forwarding exposure and spot unexpected forwarding activity.
  This query is part of the Microsoft Defender for Office 365 Detections and Insights workbook in Microsoft Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-3-build-custom-email-security-reports-with-power-bi-and-workbooks-in-micros/4490127
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - EmailEvents
tactics:
  - Collection
  - Exfiltration
relevantTechniques:
  - T1114
  - T1020
query: |
  EmailEvents
  | where Timestamp > ago(30d)
  | where EmailDirection == "Outbound" and isnotempty(ForwardingInformation)
  | extend Key = strcat(NetworkMessageId, '-', RecipientEmailAddress)
  | summarize arg_max(Timestamp, *) by Key
  | extend FwdInfo = parse_json(ForwardingInformation)
  | extend ForwardingType = tostring(FwdInfo.ForwardingType),
           ForwardingUser = tostring(FwdInfo.ForwardingUser),
           RecipientDomain = tostring(split(RecipientEmailAddress, '@')[1])
  | summarize ForwardedMessages = count(),
              ForwardingUsers = dcount(ForwardingUser),
              ExternalRecipients = dcount(RecipientEmailAddress),
              ExternalDomains = dcount(RecipientDomain)
      by ForwardingType
  | sort by ForwardedMessages desc
version: 1.0.0

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.