HuntCONSTRUCTED
Hunt: inbox rules that forward, redirect, delete or hide mail
New or changed inbox rules with forwarding, deletion or move actions, across every mailbox. The rule an attacker leaves behind to watch for invoices and hide the replies.
CollectionT1114.003T1564.008checked 2026-09-26
Needs
- The Microsoft 365 unified audit log (Exchange workload) in your SIEM
Will also return
- Users forwarding to a personal address or a delegate, which may be allowed by policy.
- Rules that file newsletters into folders. Common, and easy to tell apart by their conditions.
Reading the results
Attackers name rules with a single character, a dot, or a word that looks like housekeeping, and they filter on the vocabulary of money: invoice, payment, remittance, bank, wire. A rule created from an address the user has never signed in from, filtering on those words and moving matches to RSS Feeds, is the result this hunt exists to find.
When you find one, the first-15-minutes checklist begins with exporting it rather than deleting it.
What it misses
Forwarding set on the mailbox itself (Set-Mailbox with ForwardingSmtpAddress) is not an inbox rule. Run a second search for Set-Mailbox operations that set a forwarding address.
KQL
Microsoft SentinelUntestedOfficeActivity
| where TimeGenerated > ago(7d)
| where Operation in ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules")
| extend Params = tostring(Parameters)
| where Params has_any ("ForwardTo", "ForwardAsAttachmentTo", "RedirectTo",
"DeleteMessage", "MoveToFolder", "MarkAsRead")
| project TimeGenerated, UserId, ClientIP, Operation, Params
| order by TimeGenerated descSPL
Splunk with the Microsoft Office 365 add-onUntestedindex=o365 sourcetype="o365:management:activity" Workload=Exchange earliest=-7d
(Operation="New-InboxRule" OR Operation="Set-InboxRule" OR Operation="UpdateInboxRules")
| search "Parameters{}.Name" IN ("ForwardTo", "ForwardAsAttachmentTo", "RedirectTo", "DeleteMessage", "MoveToFolder", "MarkAsRead")
| table _time UserId ClientIP Operation "Parameters{}.Name" "Parameters{}.Value"
| sort - _timeElastic
Kibana query, Microsoft 365 integrationUntestedevent.dataset : "o365.audit" and
event.action : ("New-InboxRule" or "Set-InboxRule" or "UpdateInboxRules")