CTD-000174

Detected a malicious inbox rule to conceal email in Exchange Online

High
Entra ID Exchange Online
Collection Defense Evasion
v16

Signature Identity

CTD-000174
Threat ID
16
Version
IOC
Indicator Type

Threat Description

A threat actor who gains access to an Exchange Online mailbox may create a new inbox rule to delete, move, or forward incoming emails – tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.

The threat is detected based on the creation of new inbox rules that meet any of the following criteria:

  • Move emails to Deleted Items
  • Mark emails as Read
  • Forward emails to external domains

Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when:

  • A new inbox rule with one or more of the above suspicious actions is created
  • The rule is created by someone other than the mailbox owner (e.g., via delegated access or compromised credentials)

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

MITRE ATT&CK: Attack Tactics

Collection Defense Evasion

D3FEND: Defend Tactics

D3-ACH (Application Configuration Hardening)

Remediation

  1. Disable suspicious rules immediately.
  2. Investigate email logs for unauthorized access.
  3. Reset password and enforce MFA for compromised accounts.

Frequently Asked Questions

What does Detected a malicious inbox rule to conceal email in Exchange Online mean?

Detected a malicious inbox rule to conceal email in Exchange Online means that an unauthorized entity has created a new inbox rule in your Exchange Online mailbox, modifying the default behavior of email processing. This rule is likely configured to delete, move, or forward incoming emails without administrator knowledge or consent.

This finding is rated high severity because it enables attackers to manipulate email flow, making it challenging for administrators to detect and respond to Business Email Compromise (BEC) attacks. This can lead to unauthorized data access, financial losses, and reputational damage.

When a malicious inbox rule is present, an attacker can use it to redirect or delete incoming emails, making it difficult for administrators to detect and respond to BEC attacks. This tactic allows attackers to maintain access to the mailbox and continue their malicious activities undetected.

Cayosoft Guardian detects Detected a malicious inbox rule to conceal email in Exchange Online by continuously monitoring the creation of new inbox rules across your Exchange Online mailboxes, comparing them against known good configurations. When a suspicious rule is detected, Guardian flags it as a security issue and alerts administrators so they can take action.

Cayosoft Guardian helps reduce the risk of Detected a malicious inbox rule to conceal email in Exchange Online by alerting administrators so they can disable suspicious rules immediately. Guardian also supports ongoing monitoring, ensuring that if a malicious rule is re-created later, it will be caught quickly and administrators can take action to prevent further damage.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Exchange Online
Themes
Mailbox protection
Attack Tactics
Collection Defense Evasion
Defend Tactics
D3-ACH (Application Configuration Hardening)
Indicator Types
IOC
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical