Azure Risk Event: Suspicious Inbox Forwarding

Alerts on Azure Identity Protection risk events indicating inbox forwarding to an external address.

FreeReviewedSigma · High · v5
Product
azure
Service
riskdetection
Author
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' (SigmaHQ), DRL 1.1
Published
2023-09-03
Updated
2026-07-31
title: "Azure Risk Event: Suspicious Inbox Forwarding"
id: 193f4ee5-f232-4b22-bcd3-02c12b20b8c7
status: test
description: This rule matches an Azure risk detection event indicating suspicious inbox forwarding behavior. Attackers may use inbox forwarding to covertly collect or exfiltrate email contents by copying messages to an external destination. The detection relies on risk telemetry with riskEventType set to suspiciousInboxForwarding.
references:
  - https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#suspicious-inbox-forwarding
  - https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/identity_protection/azure_identity_protection_inbox_forwarding_rule.yml
author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule Team
date: 2023-09-03
tags:
  - attack.t1114.003
  - attack.collection
logsource:
  product: azure
  service: riskdetection
detection:
  selection:
    riskEventType: suspiciousInboxForwarding
  condition: selection
falsepositives:
  - A legitimate forwarding rule.
level: high
license: DRL-1.1
related:
  - id: 27e4f1d6-ae72-4ea0-8a67-77a73a289c3d
    type: derived