High Volume Anonymous SMTP Relay from Single IP
This rule detects a high volume of successful sign-in attempts to Exchange Online from a single IP address where the UserPrincipalName ends with '@' (indicating an anonymous or malformed UPN) and Conditional Access was not applied. This pattern can be indicative of anonymous SMTP relay abuse, often used for spamming or phishing campaigns.
Microsoft Sentinel (KQL)

