O365 Mail Forwarding and Redirecting Rule Changes

Identifies O365 mailbox/inbox rule changes that configure forwarding or redirects in audit logs.

FreeReviewedSigma · Medium · v5
Product
m365
Service
audit
Author
RedCanary Team (idea), Harjot Singh @cyb3rjy0t (SigmaHQ), DRL 1.1
Published
2023-10-11
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Impact

What it detects

This rule flags Microsoft 365 audit log events where mailbox and inbox rule operations include forwarding or redirecting parameters. Attackers commonly abuse mail forwarding/redirecting to intercept messages or maintain access by rerouting email to attacker-controlled destinations. It relies on O365 audit telemetry containing specific operations and related properties/parameters such as Forward*, RedirectTo*, and forwarding target addresses.

Related detections9 linkedT1114.003 — drag to rearrange
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
Suspicious SCATTERED SPIDER Exchange Transport Rule Creation to Suppress Alerts (via m365)
Suspicious Inbox Rule Creation With Forwarding or Deletion via M365 Exchange
Suspicious Email-Hiding Inbox Rule Creation (via exchange)
Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
Malicious Mailbox Forwarding Rule Creation (via exchange)
Suspicious Inbox Rule Moving Mail to Junk for Concealment (via m365)
O365 Mail Forwarding and Redirecting Rule Changes
Pivot detection · T1114.003 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.