2026 Critical Enterprise Intrusion Chain Detection: O365 Inbox Rule Auto-Forward/Deletion for BEC Follow-Through Hiding

Detects the creation or modification of Exchange inbox rules that involve suspicious actions, such as forwarding or redirecting emails to external domains, deleting messages, or marking messages as read. These actions are common indicators of persistent access or data exfiltration attempts following a mailbox compromise.