Azure risk event: Suspicious inbox manipulation rules that delete or move messages or folders

Alerts on Azure risk events for suspicious inbox rules that delete or move mailbox items.

FreeReviewedSigma · High · v5
Product
azure
Service
riskdetection
Author
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' (SigmaHQ), DRL 1.1
Published
2023-09-03
Updated
2026-07-31
title: "Azure risk event: Suspicious inbox manipulation rules that delete or move messages or folders"
id: 2f580dbd-0e59-4acd-9b82-42b2019cf275
status: test
description: This rule flags an Azure risk detection event indicating suspicious inbox manipulation rules that delete or move messages or folders within a user’s inbox. Attackers can use inbox rules to hide their activity, reroute communications, or degrade user visibility while maintaining persistence. The detection relies on Azure risk telemetry with the riskEventType value mcasSuspiciousInboxManipulationRules.
references:
  - https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#suspicious-inbox-manipulation-rules
  - https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/azure/identity_protection/azure_identity_protection_inbox_manipulation.yml
author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule Team
date: 2023-09-03
tags:
  - attack.stealth
  - attack.t1140
logsource:
  product: azure
  service: riskdetection
detection:
  selection:
    riskEventType: mcasSuspiciousInboxManipulationRules
  condition: selection
falsepositives:
  - Actual mailbox rules that are moving items based on their workflow.
level: high
license: DRL-1.1
related:
  - id: ceb55fd0-726e-4656-bf4e-b585b7f7d572
    type: derived