Exchange user mailbox forwarding
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection, Email
ATT&CK Tactic
Collection (TA0009), Exfiltration (TA0010)
ATT&CK Technique
Email Collection: Email Forwarding Rule (T1114.003), Automated Exfiltration (T1020), Email Collection (T1114)
Severity
Low
Description
A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient.
Attacker's Goals
Leverage a compromised user account to modify a mailbox's settings to forward emails to an external recipient and collect sensitive information.
Investigative actions
Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity).
Check if the forwarding domain is an unknown external domain.
Investigate the IP address associated with the rule.
Follow further actions done by the account.
Variations
Was this helpful?
