← Back to SOC feed Coverage →

Top External Recipients Receiving Auto-forwarded Email (Mailbox Rule and SMTP)

kql MEDIUM Azure-Sentinel
T1114T1020
EmailEvents
huntingmicrosoftofficial
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Azure-Sentinel →
Retrieved: 2026-09-03T11:00:00Z · Confidence: medium

Hunt Hypothesis

This hypothesis targets adversaries who establish persistent email forwarding rules to exfiltrate sensitive data or maintain covert communication channels, aligning with MITRE techniques T1114 (Network Sniffing) and T1020 (Automated Exfiltration). Proactively hunting for these patterns in Azure Sentinel is critical because automated forwarding to external domains often bypasses standard user awareness, allowing threat actors to siphon information or receive command-and-control instructions without triggering immediate user suspicion.

KQL Query

EmailEvents
| where Timestamp > ago(30d)
| where EmailDirection == "Outbound" and isnotempty(ForwardingInformation)
| extend Key = strcat(NetworkMessageId, '-', RecipientEmailAddress)
| summarize arg_max(Timestamp, *) by Key
| extend FwdInfo = parse_json(ForwardingInformation)
| extend ForwardingType = tostring(FwdInfo.ForwardingType),
         ForwardingUser = tostring(FwdInfo.ForwardingUser)
| summarize ForwardedMessages = count(),
            ForwardingUsers = dcount(ForwardingUser)
    by RecipientEmailAddress, ForwardingType
| top 20 by ForwardedMessages

Analytic Rule Definition

id: db98ab11-e0c2-4ece-9b31-1131bbdd7647
name: Top External Recipients Receiving Auto-forwarded Email (Mailbox Rule and SMTP)
description: |
  This query lists the top external recipients receiving automatically forwarded email, by forwarding type, using the EmailEvents table.
description-detailed: |
  Auto-forwarding to an external recipient is a common data-exfiltration technique after mailbox compromise. This query ranks the external recipient addresses receiving auto-forwarded mail, split by forwarding type (mailbox rule versus SMTP forwarding), with the count of forwarded messages and the distinct internal forwarding users. External addresses receiving high volumes from one or more internal users are worth investigating.
  This query is part of the Microsoft Defender for Office 365 Detections and Insights workbook in Microsoft Sentinel: https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/part-3-build-custom-email-security-reports-with-power-bi-and-workbooks-in-micros/4490127
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - EmailEvents
tactics:
  - Collection
  - Exfiltration
relevantTechniques:
  - T1114
  - T1020
query: |
  EmailEvents
  | where Timestamp > ago(30d)
  | where EmailDirection == "Outbound" and isnotempty(ForwardingInformation)
  | extend Key = strcat(NetworkMessageId, '-', RecipientEmailAddress)
  | summarize arg_max(Timestamp, *) by Key
  | extend FwdInfo = parse_json(ForwardingInformation)
  | extend ForwardingType = tostring(FwdInfo.ForwardingType),
           ForwardingUser = tostring(FwdInfo.ForwardingUser)
  | summarize ForwardedMessages = count(),
              ForwardingUsers = dcount(ForwardingUser)
      by RecipientEmailAddress, ForwardingType
  | top 20 by ForwardedMessages
version: 1.0.0

Required Data Sources

Sentinel TableNotes
EmailEventsEnsure this data connector is enabled

MITRE ATT&CK Context

References

False Positive Guidance

Original source: https://github.com/Azure/Azure-Sentinel/blob/main/Hunting Queries/Microsoft 365 Defender/Email and Collaboration Queries/Mailflow/Top External Recipients Receiving Auto-forwarded Email.yaml