Malicious Office 365 Email Forwarding Rule to External Domain (via office365)

PremiumReviewedSigma · High · v1
Product
azure
Service
office365
Author
HuntRule
Published
2026-05-14
Updated
2026-08-28

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creates a forwarding rules to a non company email in order to collect information.

Related detections8 linkedT1114.003 — drag to rearrange
Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
Malicious Mailbox Forwarding Rule Creation (via exchange)
Google Workspace login activity: Out-of-domain email forwarding
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
O365 Mail Forwarding and Redirecting Rule Changes
Azure Risk Event: Suspicious Inbox Forwarding
Malicious Office 365 Email Forwarding Rule to External Domain (via office365)
Pivot detection · T1114.003 · 8 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.