Suspicious Email-Hiding Inbox Rule Creation (via exchange)

PremiumReviewedSigma · Medium · v1
Product
m365
Service
exchange
Author
HuntRule
Published
2026-09-05
Updated
2026-09-05

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creation of a mailbox rule that automatically deletes messages or moves them to obscure folders such as RSS Feeds or Junk, a defense-evasion behavior adversaries use to hide security alerts and their own correspondence after account compromise. Email-hiding rules feature in the Red Canary Threat Detection Report as a post-compromise persistence and evasion tactic in business email compromise. Detecting these rules surfaces attacker efforts to stay unnoticed.

Related detections5 linkedT1564.008 — drag to rearrange
Suspicious Inbox Rule Moving Mail to Junk for Concealment (via m365)
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
O365 Mail Forwarding and Redirecting Rule Changes
Suspicious Email-Hiding Inbox Rule Creation (via exchange)
Pivot detection · T1564.008 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.