Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions

Flags M365 audit events where inbox rules are created/updated with parameters that can delete, mark, move, or keyword-match messages.

FreeReviewedSigma · Medium · v5
Product
m365
Service
audit
Author
Marco Pedrinazzi (@pedrinazziM) (InTheCyber) (SigmaHQ), DRL 1.1
Published
2026-01-09
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Microsoft 365 mailbox activity where an inbox rule is created or updated, specifically when the rule parameters include actions such as deleting messages, marking messages as read, moving messages to folders, or matching subject/body content. Attackers use inbox rules to alter the handling of incoming emails, helping evade review by suppressing or redirecting messages. The detection relies on M365 audit log events for inbox rule operations and on matching specific parameter values in those events.

Related detections9 linkedT1114.003 — drag to rearrange
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
O365 Mail Forwarding and Redirecting Rule Changes
Suspicious SCATTERED SPIDER Exchange Transport Rule Creation to Suppress Alerts (via m365)
Suspicious Inbox Rule Creation With Forwarding or Deletion via M365 Exchange
Suspicious Email-Hiding Inbox Rule Creation (via exchange)
Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
Malicious Mailbox Forwarding Rule Creation (via exchange)
Suspicious Inbox Rule Moving Mail to Junk for Concealment (via m365)
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
Pivot detection · T1114.003 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.