Purview SIT Email Scanner Tool v2 Update

Purview SIT Email Scanner Tool v2 Update
i haven't seen the sun in days

Guess what we're baaaaaack.

December/January are rough here in Cleveland, man. But, I've got some updates pushed out for the Purview SIT Email Scanner Tool that you might want to check out 🙂

Shout out to Emily Spotts for her collaboration on this one.

What was changed

  • Added parallel processing for multiple mailboxes simultaneously
  • Fixed double API call (now fetches body in first request)
  • Added pagination support for mailboxes with >1000 messages
  • Configurable throttling and parallel execution limits
  • Restored credential scanning functionality (GitHub PAT, Google API, Slack, Azure, JWT, SQL, etc.)
  • Added exclusions for Guest accounts (thanks Romain Dalle)

As you can see from the table below, these changes have significantly improved performance.

gotta go fast 🏃‍➡️🏃‍➡️🏃‍➡️

Script in action...

running with default params
batch processing of messages
report export, total matches found, and success message

The data...

look at all of that sensitive data just sitting in user's mailboxes 😱


If you were using the old version and it took days to run and still didn't pull everything...this will solve it. Don't hesitate to ping me with feature requests, issues, or general concerns!

Looking forward to dropping more content this year 😊


New here? Wondering why I went through the effort to make this tool? Check it out:

Recap: Finding SITs in Exchange Mail at Rest
I didn’t have much of a following when I initially wrote about SIT-search limitations in mailbox data-at-rest. Since then, I’ve spoken with multiple clients and data security professionals who were under the mistaken impression that Purview could find that data. Since this limitation still exists, and since it’s still an

Read more