Microsoft 365 inbound suspicious email delivered to Inbox or Junk

Alerts when Defender-labeled suspicious inbound emails are delivered to user Inbox/Junk in Microsoft 365.

FreeReviewedSigma · Medium · v4
Product
m365
Service
audit
Author
Marco Pedrinazzi (@pedrinazziM) (InTheCyber) (SigmaHQ), DRL 1.1
Published
2026-01-27
Updated
2026-07-31

ATT&CK techniques

Initial Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Microsoft 365 mailbox audit events where the Threat Intelligence engine flags an inbound email as malicious or suspicious and it is delivered to a user’s Inbox or Junk. Delivery to an end-user can indicate that the message bypassed initial blocking and warrants follow-up to assess potential spearphishing or malicious content. The detection relies on audit telemetry that includes workload, operation, directionality, and the delivery action outcome.

Related detections9 linkedT1566.002 — drag to rearrange
Suspicious Cloudflare Workers Brand-Impersonation Phishing Domains via Proxy
Suspicious NFe-Themed Brazilian Lure Executable Execution
Suspicious mstsc Launch of RDP File From User Download or Temp Path (via process_creation)
Suspicious Regsvr32 Squiblydoo Remote Scriptlet Execution via Command Line (via process_creation)
Suspicious Phishing URL with Unrendered Template Placeholder (via proxy)
Suspicious Spoofed Inbound Email With Failed Authentication and Anonymous Internal Sender (via m365)
Malicious Credential Harvesting Request via All-in-1 PHP Endpoint (via proxy)
Possible Mamba 2FA AiTM Phishing URL Pattern
Suspicious Error 524 Decoy Smishing Phishing Endpoint Access (via proxy)
Microsoft 365 inbound suspicious email delivered to Inbox or Junk
Pivot detection · T1566.002 · 9 related

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.