Suspicious Inbox Rule Creation With Forwarding or Deletion via M365 Exchange

PremiumReviewedSigma · Medium · v1
Product
m365
Service
exchange
Author
HuntRule
Published
2026-09-10
Updated
2026-09-10

ATT&CK techniques

Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects the creation or modification of a mailbox inbox rule that forwards, redirects, or deletes messages within Microsoft 365 Exchange, matching the mail-exfiltration tradecraft of the ARToken EvilTokens affiliate panel reported by Cisco Talos. After token theft the operators plant inbox rules to silently siphon or hide victim mail. This behavior signals attacker persistence and collection inside a compromised tenant.

Related detections9 linkedT1114.003 — drag to rearrange
Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
Malicious Mailbox Forwarding Rule Creation (via exchange)
Malicious Office 365 Email Forwarding Rule to External Domain (via office365)
Google Workspace login activity: Out-of-domain email forwarding
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
O365 Mail Forwarding and Redirecting Rule Changes
Azure Risk Event: Suspicious Inbox Forwarding
Suspicious Inbox Rule Creation With Forwarding or Deletion via M365 Exchange
Pivot detection · T1114.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.