Suspicious Inbox Rule Moving Mail to Junk for Concealment (via m365)

PremiumReviewedSigma · Medium · v1
Product
m365
Service
exchange
Author
HuntRule
Published
2026-07-08
Updated
2026-08-28

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects creation or modification of a mailbox inbox rule that moves incoming messages to the junk email folder. Threat actors created such rules to hide fraud notifications and security alerts from the victim while automating financially driven attacks.

Related detections5 linkedT1564.008 — drag to rearrange
Suspicious Email-Hiding Inbox Rule Creation (via exchange)
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
O365 Mail Forwarding and Redirecting Rule Changes
Suspicious Inbox Rule Moving Mail to Junk for Concealment (via m365)
Pivot detection · T1564.008 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.