Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity

Detects PowerShell script content using Exchange cmdlets to create or update inbox rules with message-manipulation actions.

FreeReviewedSigma · Medium · v5
Product
windows
Category
ps_script
Author
Marco Pedrinazzi (@pedrinazziM) (InTheCyber) (SigmaHQ), DRL 1.1
Published
2026-02-10
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags PowerShell script block content that invokes Exchange cmdlets New-InboxRule or Set-InboxRule, indicating an inbox rule was created or modified. Attackers may use inbox rules to hide or manipulate incoming email, such as moving messages to other folders, marking them as read, deleting them, or filtering based on subject/body content. It relies on Script Block Logging telemetry where ScriptBlockText is available and contains both the cmdlet call and specific inbox rule actions or match conditions.

Related detections9 linkedT1114.003 — drag to rearrange
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
O365 Mail Forwarding and Redirecting Rule Changes
Suspicious SCATTERED SPIDER Exchange Transport Rule Creation to Suppress Alerts (via m365)
Suspicious Inbox Rule Creation With Forwarding or Deletion via M365 Exchange
Suspicious Email-Hiding Inbox Rule Creation (via exchange)
Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
Malicious Mailbox Forwarding Rule Creation (via exchange)
Suspicious Inbox Rule Moving Mail to Junk for Concealment (via m365)
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Pivot detection · T1114.003 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.