Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows

Alerts when PowerShell script blocks reference Exchange inbox/rule cmdlets and forwarding/redirect parameters.

FreeReviewedSigma · Medium · v5
Product
windows
Category
ps_script
Author
Nasreddine Bencherchali (Nextron Systems), Marco Pedrinazzi (@pedrinazziM) (InTheCyber) (SigmaHQ), DRL 1.1
Published
2026-03-01
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Impact

What it detects

This rule identifies PowerShell script block activity that includes Exchange mailbox/inbox rule cmdlet usage associated with creating or modifying email forwarding and redirecting behavior. Attackers commonly use mailbox rule changes to reroute messages to attacker-controlled recipients while avoiding direct email tampering, making this a key stealth and persistence signal. It relies on Windows PowerShell Script Block Logging telemetry and matches specific cmdlets and forwarding/redirect parameters within recorded script content.

Related detections9 linkedT1114.003 — drag to rearrange
O365 Mail Forwarding and Redirecting Rule Changes
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
Suspicious SCATTERED SPIDER Exchange Transport Rule Creation to Suppress Alerts (via m365)
Suspicious Inbox Rule Creation With Forwarding or Deletion via M365 Exchange
Suspicious Email-Hiding Inbox Rule Creation (via exchange)
Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
Malicious Mailbox Forwarding Rule Creation (via exchange)
Suspicious Inbox Rule Moving Mail to Junk for Concealment (via m365)
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Pivot detection · T1114.003 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.