New Inbox Forwarding Rule¶
Alert¶
A new or changed inbox rule that forwards or redirects mail, deletes it, or moves it to a rarely used folder; or mailbox-level forwarding (ForwardingSmtpAddress) set to an external address.
Why It Matters¶
This is the most common persistence technique in business email compromise. Attackers forward a copy of everything to themselves, or quietly move replies from a vendor or customer into RSS Feeds or Archive so the real user never sees the conversation the attacker is having in their name.
ATT&CK¶
Questions I Answer¶
- What does the rule do? Forwarding to an external address, deleting messages, or moving them to RSS Feeds, Archive, Conversation History, or a new folder with a one-character name are the patterns I look for.
- What are the conditions? Rules that match keywords like "invoice", "payment", "wire", "bank", or a specific vendor's domain are a strong BEC sign.
- Where was the rule created from? The client IP on the audit event. If it matches a sign-in the user does not recognize, the account is compromised.
- Does the user know about it? Some users do set up legitimate forwarding to a personal address, which is its own policy problem but not an intrusion.
Queries¶
Rule and forwarding changes:
OfficeActivity
| where TimeGenerated > ago(7d)
| where Operation in ("New-InboxRule", "Set-InboxRule", "UpdateInboxRules", "Set-Mailbox")
| where Parameters has_any ("ForwardTo", "RedirectTo", "ForwardAsAttachmentTo", "ForwardingSmtpAddress", "DeleteMessage", "MoveToFolder")
| project TimeGenerated, UserId, ClientIP, Operation, Parameters
Sign-ins from the IP that created the rule:
SigninLogs
| where TimeGenerated > ago(7d)
| where IPAddress == "203.0.113.10"
| project TimeGenerated, UserPrincipalName, Location, AppDisplayName, UserAgent, ResultType
Current state in Exchange Online PowerShell:
Get-InboxRule -Mailbox user@example.com | Format-List Name, Enabled, From, SubjectContainsWords, BodyContainsWords, MoveToFolder, ForwardTo, RedirectTo, DeleteMessage
Get-Mailbox user@example.com | Format-List ForwardingSmtpAddress, ForwardingAddress, DeliverToMailboxAndForward
Verdict¶
- True positive: the user did not create it, or it was created from an unfamiliar IP, or it hides finance-related mail
- Benign true positive: the user created it intentionally; I still check it against policy on external forwarding
- False positive: a rule created by IT or a mail migration tool
Escalate¶
Compromised Account / BEC. I export the rule details before removing it so the evidence is preserved.