Exchange email-hiding inbox rule
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection, Email
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Hide Artifacts: Email Hiding Rules (T1564.008)
Severity
Informational
Description
A user configured an Exchange inbox rule that may be used to hide emails.
Attacker's Goals
Prevent an organization from warning users that they've been compromised (e.g. an internal spear-phishing campaign).
Investigative actions
Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity).
Investigate the IP address associated with the rule.
Review the rule keywords for suspicious or malicious terms.
Follow further actions done by the account.
Check for a possible phishing campaign on the organization.
Look for multiple instances of email hiding, which may be an indication of a larger campaign.
Check if the user regularly configures inbox rules.
Variations
Was this helpful?
