Microsoft 365 Cloud App Security Alerts on Suspicious Inbox Forwarding Rules

Flags successful Microsoft Cloud App Security alerts for suspicious inbox forwarding behavior.

FreeReviewedSigma · Low · v4
Product
m365
Service
threat_management
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-08-22
Updated
2026-07-31

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule identifies successful “Suspicious inbox forwarding” events reported by Microsoft Cloud App Security (Microsoft 365). Attackers commonly abuse inbox forwarding to exfiltrate email content by silently copying or forwarding messages to an external destination. Detection relies on threat management telemetry from the SecurityComplianceCenter service, including the event source, event name, and success status.

Related detections9 linkedT1020 — drag to rearrange
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
AWS CloudTrail: RDS Cluster Modification or Deletion (ModifyDBCluster/DeleteDBCluster)
GitHub Audit Log: Repository or Organization Transfer Detected
GitHub Audit Logs: Private/Internal Forking Policy Enabled or Cleared
O365 Mail Forwarding and Redirecting Rule Changes
PowerShell Script Reading Files and Resolving DNS Host Entries
PowerShell script exfiltration using Invoke-WebRequest with POST or PUT
AWS CloudTrail RDS ModifyDBInstance Master User Password Change
AWS CloudTrail: RestoreDBInstanceFromDBSnapshot Creates Public RDS Instance
Microsoft 365 Cloud App Security Alerts on Suspicious Inbox Forwarding Rules
Pivot detection · T1020 · 9 related

Changelog

v4
  1. v4
    Candidate ingested via manual entry.2026-07-31
  2. v3
    Candidate ingested via manual entry.2026-07-31
  3. v2
    Candidate ingested via manual entry.2026-07-31
  4. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.