Suspicious Exchange Online Mail Flow Rule or Connector Creation via Compromised Account

PremiumReviewedSigma · Medium · v1
Product
m365
Service
exchange
Author
HuntRule
Published
2026-05-27
Updated
2026-08-28

ATT&CK techniques

Persistence → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects creation or modification of Exchange Online transport rules, inbound connectors, or DKIM signing configuration, matching post-compromise mailbox tampering observed in the Kali365 device code phishing ecosystem. Adversaries add mail flow rules and connectors to reroute, hide, or spoof mail after taking over an account. These mailbox-infrastructure changes support business email compromise and mass phishing distribution.

Related detections3 linkedT1098.005 — drag to rearrange
Suspicious Device Registration Following OAuth Token Theft
Suspicious Workday Payment Election Change via Compromised Account (via workday)
Possible Rogue Device Registration in Entra ID After Device Code Phishing
Suspicious Exchange Online Mail Flow Rule or Connector Creation via Compromised Account
Pivot detection · T1098.005 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.