CTD-000031

Exchange Online mailbox with SMTP forwarding address

Informational
Entra ID Exchange Online
Defense Evasion Persistence
v41

Signature Identity

CTD-000031
Threat ID
41
Version
IOC-IOE
Indicator Type

Threat Description

Exchange Online mailbox with SMTP forwarding address might be an indication of threat activities. A threat actor might use an SMTP forwarding address to receive emails from the compromised mailbox.

MITRE ATT&CK: Attack Tactics

Defense Evasion Persistence

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

  1. Review list of SMTP forwarding addresses in Evidence section.
  2. To remove SMTP forwarding address using Exchange Online PowerShell module:
    1. Connect to your Exchange Online PowerShell using cmdlet Connect-ExchangeOnline.
    2. Remove SMTP forwarding addresses using Set-Mailbox {Identity} -ForwardingSmtpAddress $null.

Frequently Asked Questions

What does Exchange Online mailbox with SMTP forwarding address mean?

An Exchange Online mailbox has an SMTP forwarding address configured, allowing emails to be redirected to another location. This setting can indicate a potential security issue if not properly managed.

This configuration is rated informational severity because it indicates a potential means for threat actors to receive emails from compromised mailboxes, but does not directly enable compromise or administrative access. The attacker gains the ability to intercept and redirect emails, which can support later attacker activity such as reconnaissance and persistence.

Attackers might use an Exchange Online mailbox with an SMTP forwarding address to receive emails from a compromised mailbox, allowing them to gather information. This configuration can serve as a means for threat actors to maintain persistence and support later attacker activity such as lateral movement.

Cayosoft Guardian continuously monitors the configuration of email accounts in the organization's Microsoft 365 environment, identifying and flagging any instances where an SMTP forwarding address is set. This allows administrators to take proactive measures to prevent potential security issues.

Cayosoft Guardian alerts administrators to the presence of SMTP forwarding addresses, enabling them to review and remove any unnecessary or potentially malicious configurations. This proactive approach supports ongoing security by providing visibility into potential attack paths and assisting response efforts.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Entra ID Exchange Online
Themes
Mailbox protection
Attack Tactics
Defense Evasion Persistence
Defend Tactics
Application Configuration Hardening
Indicator Types
IOC IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical