Suspicious Mailbox Forwarding Rule Creation Following AiTM Phishing

PremiumReviewedSigma · Medium · v1
Product
m365
Service
exchange
Author
HuntRule
Published
2026-09-20
Updated
2026-09-20

ATT&CK techniques

Initial Access → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects the creation or modification of mailbox inbox rules that forward, redirect, or delete incoming messages, a common post-compromise action performed by operators of the Sneaky2FA adversary-in-the-middle phishing kit. After stealing session tokens attackers add hidden forwarding rules to maintain access to victim correspondence, so this activity is a key sign of business email compromise.

Related detections9 linkedT1078 — drag to rearrange
Suspicious Salesforce OAuth Refresh Token Use by Klue Battlecards App
Suspicious Salesforce Bulk Query by External App with Python-urllib Agent
Suspicious Inbox Rule Creation With Forwarding or Deletion via M365 Exchange
Possible Next.js Middleware Auth Bypass via X-Middleware-Subrequest Header (CVE-2025-29927)
Suspicious Brutforce with Denied Access Due to Account Restrictions Policies (via security)
Suspicious Success Login Attempt on a Windows OpenSSH Server (via security)
Suspicious SQL Server - Connection Attempt Using a Disabled Account (via application)
Suspicious Lateral Movement Detection - Based on "special Groups" Feature (via security)
Malicious Exchange Inbox Rule Hiding Workday Payroll Notifications via Payroll Pirate Compromise (via m365)
Suspicious Mailbox Forwarding Rule Creation Following AiTM Phishing
Pivot detection · T1078 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.