Azure Risk Event: Suspicious Inbox Forwarding

Alerts on Azure Identity Protection risk events indicating inbox forwarding to an external address.

FreeReviewedSigma · High · v5
Product
azure
Service
riskdetection
Author
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' (SigmaHQ), DRL 1.1
Published
2023-09-03
Updated
2026-07-31

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule matches an Azure risk detection event indicating suspicious inbox forwarding behavior. Attackers may use inbox forwarding to covertly collect or exfiltrate email contents by copying messages to an external destination. The detection relies on risk telemetry with riskEventType set to suspiciousInboxForwarding.

Related detections9 linkedT1114.003 — drag to rearrange
Suspicious Inbox Rule Creation With Forwarding or Deletion via M365 Exchange
Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
Malicious Mailbox Forwarding Rule Creation (via exchange)
Malicious Office 365 Email Forwarding Rule to External Domain (via office365)
Google Workspace login activity: Out-of-domain email forwarding
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
O365 Mail Forwarding and Redirecting Rule Changes
Azure Risk Event: Suspicious Inbox Forwarding
Pivot detection · T1114.003 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.