Azure mailbox rule creation
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: Azure Audit Log OR Microsoft Graph Logs
Detection Modules
Cloud
Detector Tags
Microsoft Graph Activity Logs
ATT&CK Tactic
Collection (TA0009), Stealth (TA0005)
ATT&CK Technique
Email Collection: Email Forwarding Rule (T1114.003), Indicator Removal: Clear Mailbox Data (T1070.008)
Severity
Informational
Description
A Mailbox rule in Azure was created.
Attacker's Goals
Intercept or exfiltrate sensitive information.
Investigative actions
Investigate the rule's details and confirm its legitimacy.
Look for any unusual behavior originated from the suspected identity, and check if they're compromised.
Variations
Was this helpful?
