HuntCONSTRUCTED

Hunt: inbox rules that forward, redirect, delete or hide mail

New or changed inbox rules with forwarding, deletion or move actions, across every mailbox. The rule an attacker leaves behind to watch for invoices and hide the replies.

CollectionT1114.003T1564.008checked 2026-09-26

Needs

  • The Microsoft 365 unified audit log (Exchange workload) in your SIEM

Will also return

  • Users forwarding to a personal address or a delegate, which may be allowed by policy.
  • Rules that file newsletters into folders. Common, and easy to tell apart by their conditions.

Reading the results

Attackers name rules with a single character, a dot, or a word that looks like housekeeping, and they filter on the vocabulary of money: invoice, payment, remittance, bank, wire. A rule created from an address the user has never signed in from, filtering on those words and moving matches to RSS Feeds, is the result this hunt exists to find.

When you find one, the first-15-minutes checklist begins with exporting it rather than deleting it.

What it misses

Forwarding set on the mailbox itself (Set-Mailbox with ForwardingSmtpAddress) is not an inbox rule. Run a second search for Set-Mailbox operations that set a forwarding address.

KQL

Microsoft SentinelUntestedwindow: 7 days, set in the query

Parameters holds the rule's conditions and actions. Read the SubjectContainsWords, BodyContainsWords and From parameters on every hit: they are the intent.

OfficeActivity
| where TimeGenerated > ago(7d)
| where Operation in ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules")
| extend Params = tostring(Parameters)
| where Params has_any ("ForwardTo", "ForwardAsAttachmentTo", "RedirectTo",
                        "DeleteMessage", "MoveToFolder", "MarkAsRead")
| project TimeGenerated, UserId, ClientIP, Operation, Params
| order by TimeGenerated desc

SPL

Splunk with the Microsoft Office 365 add-onUntestedwindow: 7 days, set with earliest
index=o365 sourcetype="o365:management:activity" Workload=Exchange earliest=-7d
  (Operation="New-InboxRule" OR Operation="Set-InboxRule" OR Operation="UpdateInboxRules")
| search "Parameters{}.Name" IN ("ForwardTo", "ForwardAsAttachmentTo", "RedirectTo", "DeleteMessage", "MoveToFolder", "MarkAsRead")
| table _time UserId ClientIP Operation "Parameters{}.Name" "Parameters{}.Value"
| sort - _time

Elastic

Kibana query, Microsoft 365 integrationUntestedwindow: 7 days, set in the time picker

A Kibana query to find the events. Open o365.audit.Parameters on each hit to read the rule.

event.dataset : "o365.audit" and
event.action : ("New-InboxRule" or "Set-InboxRule" or "UpdateInboxRules")

sources

  1. Microsoft Learn: OfficeActivity table reference · primary
  2. Microsoft Learn: audit log activities
  3. Splunk: Microsoft Office 365 add-on
  4. Elastic: Filebeat o365 module

Tags: hunting · bec · email · m365 · inbox-rule · sentinel · splunk · elastic · T1114.003 · T1564.008