O365 Mail Forwarding and Redirecting Rule Changes

Identifies O365 mailbox/inbox rule changes that configure forwarding or redirects in audit logs.

FreeReviewedSigma · Medium · v5
Product
m365
Service
audit
Author
RedCanary Team (idea), Harjot Singh @cyb3rjy0t (SigmaHQ), DRL 1.1
Published
2023-10-11
Updated
2026-07-31
title: O365 Mail Forwarding and Redirecting Rule Changes
id: 3be656d1-0ed1-4438-9bda-399d201592f3
status: test
description: This rule flags Microsoft 365 audit log events where mailbox and inbox rule operations include forwarding or redirecting parameters. Attackers commonly abuse mail forwarding/redirecting to intercept messages or maintain access by rerouting email to attacker-controlled destinations. It relies on O365 audit telemetry containing specific operations and related properties/parameters such as Forward*, RedirectTo*, and forwarding target addresses.
references:
  - https://redcanary.com/blog/email-forwarding-rules/
  - https://github.com/PwC-IR/Business-Email-Compromise-Guide/blob/fe29ce06aef842efe4eb448c26bbe822bf5b895d/PwC-Business_Email_Compromise-Guide.pdf
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/cloud/m365/audit/microsoft365_susp_email_forwarding_activity.yml
author: RedCanary Team (idea), Harjot Singh @cyb3rjy0t, Huntrule Team
date: 2023-10-11
modified: 2024-11-17
tags:
  - attack.collection
  - attack.stealth
  - attack.t1114.003
  - attack.t1564.008
  - attack.exfiltration
  - attack.t1020
  - detection.threat-hunting
logsource:
  service: audit
  product: m365
  definition: "Requirements: The 'OperationProperties' and 'Parameters' fields are a list of dict. A correct mapping to the 'Value' field inside is recommended to avoid greedy search"
detection:
  selection_updateinbox:
    Operation|contains: UpdateInboxRules
    OperationProperties|contains:
      - Forward
      - Recipients
  selection_setmailbox:
    Operation|contains: Set-Mailbox
    Parameters|contains:
      - ForwardingSmtpAddress
      - ForwardingAddress
  selection_setinbox:
    Operation|contains:
      - New-InboxRule
      - Set-InboxRule
    Parameters|contains:
      - ForwardAsAttachmentTo
      - ForwardingAddress
      - ForwardingSmtpAddress
      - ForwardTo
      - RedirectTo
      - RedirectToRecipients
  condition: 1 of selection_*
falsepositives:
  - False positives are expected from legitimate mail forwarding rules. You need organisation specific knowledge. Filter out the domains that are allowed as forwarding targets as well as any additional metadata that you can use for exclusion from trusted sources/targets in order to promote this to a potential detection rule.
level: medium
license: DRL-1.1
related:
  - id: c726e007-2cd0-4a55-abfb-79730fbedee5
    type: derived