Suspicious SCATTERED SPIDER Exchange Transport Rule Creation to Suppress Alerts (via m365)

PremiumReviewedSigma · Medium · v1
Product
m365
Service
exchange
Author
HuntRule
Published
2026-09-13
Updated
2026-09-13

ATT&CK techniques

Defense Evasion → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation or modification of Exchange Online transport rules. SCATTERED SPIDER created transport rules to delete or redirect security notification emails so that suspicious-activity alerts never reached defenders. Attacker-created mail-flow rules that hide alerting are a strong evasion signal.

Related detections7 linkedT1564.008 — drag to rearrange
Suspicious Email-Hiding Inbox Rule Creation (via exchange)
Suspicious Inbox Rule Moving Mail to Junk for Concealment (via m365)
Suspicious Exchange Online Mail Flow Rule or Connector Creation via Compromised Account
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
O365 Mail Forwarding and Redirecting Rule Changes
Suspicious SCATTERED SPIDER Exchange Transport Rule Creation to Suppress Alerts (via m365)
Pivot detection · T1564.008 · 7 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.