Azure Risk Event: Suspicious Inbox Forwarding
Alerts on Azure Identity Protection risk events indicating inbox forwarding to an external address.
FreeReviewedSigma · High · v5
- Product
- azure
- Service
- riskdetection
- Author
- Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' (SigmaHQ), DRL 1.1
- Published
- 2023-09-03
- Updated
- 2026-07-31
ATT&CK techniques
CollectionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule matches an Azure risk detection event indicating suspicious inbox forwarding behavior. Attackers may use inbox forwarding to covertly collect or exfiltrate email contents by copying messages to an external destination. The detection relies on risk telemetry with riskEventType set to suspiciousInboxForwarding.
Reporting behind it
- learn.microsoft.comhttps://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#suspicious-inbox-forwarding
- learn.microsoft.comhttps://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/identity_protection/azure_identity_protection_inbox_forwarding_rule.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
azure-risk-detection-suspicious-inbox-forwarding-identity-protection-events-27e4f1d6
title: "Azure Risk Event: Suspicious Inbox Forwarding"
id: 193f4ee5-f232-4b22-bcd3-02c12b20b8c7
status: test
description: This rule matches an Azure risk detection event indicating suspicious inbox forwarding behavior. Attackers may use inbox forwarding to covertly collect or exfiltrate email contents by copying messages to an external destination. The detection relies on risk telemetry with riskEventType set to suspiciousInboxForwarding.
references:
- https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#suspicious-inbox-forwarding
- https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/identity_protection/azure_identity_protection_inbox_forwarding_rule.yml
author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule Team
date: 2023-09-03
tags:
- attack.t1114.003
- attack.collection
logsource:
product: azure
service: riskdetection
detection:
selection:
riskEventType: suspiciousInboxForwarding
condition: selection
falsepositives:
- A legitimate forwarding rule.
level: high
license: DRL-1.1
related:
- id: 27e4f1d6-ae72-4ea0-8a67-77a73a289c3d
type: derived