2026 Critical Enterprise Intrusion Chain Detection: Mass Mailbox Inbox Rule Creation for External Auto-Forwarding
Detects the creation or modification of Microsoft 365/Exchange inbox rules that suggest malicious staging or exfiltration activities. This includes rules configured for external email auto-forwarding, automatic deletion of messages, or movement of emails into hidden/system folders (e.g., RSS Subscriptions, Archive) which may be filtered based on sensitive keywords related to financial or credential theft (e.g., invoice, wire, payment).
Microsoft Sentinel (KQL)

