Malicious Mailbox Audit Bypass Association in Exchange Online (via exchange)

PremiumReviewedSigma · High · v1
Product
m365
Service
exchange
Author
HuntRule
Published
2026-09-05
Updated
2026-09-05

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects an account being added to the mailbox audit bypass list, which stops Exchange from logging that account's mailbox actions, a defense-evasion technique used to hide mailbox access and rule creation. Mailbox audit bypass is tracked in the Red Canary Threat Detection Report cloud coverage. Detecting this operation surfaces an attacker suppressing mailbox telemetry.

Related detections5 linkedT1685.002 — drag to rearrange
Suspicious AWS CloudTrail Logging Disabled
Suspicious GCP Log Sink Tampering for Defense Evasion (via gcp)
AWS CloudTrail GuardDuty Detector Deleted or Disabled via UpdateDetector
AWS CloudTrail: AWS Config Delivery Channel/Recorder Disabled
AWS CloudTrail Trail Stop/Update/Delete Activity
Malicious Mailbox Audit Bypass Association in Exchange Online (via exchange)
Pivot detection · T1685.002 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.