Detect Reply-All Attacks on Distribution Lists
This rule detects potential 'reply-all' storm attacks or malicious mass emails sent to large distribution lists within the organization. It identifies emails sent to 50 or more recipients where the subject line contains phrases like 'reply all' or 'all members', originating from an internal company domain. The rule then counts such broadcast emails within one-hour bins to identify unusual activity.
Microsoft Sentinel (KQL)

