logo

Attackers Create Inbox Rules. They Don't Rewrite Yours. by Stephan Hoehl

ID: 0622d4be-0e47-5d81-9f12-852b9c76a28e

STIX ID: report--0622d4be-0e47-5d81-9f12-852b9c76a28e

Feed Name: Vectra AI Blog

Threat Score
25/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

...
...

This Vectra AI analysis describes how threat actors abuse Microsoft 365 mailbox rules following account takeover: attackers typically create new, minimally named rules, prefer default folders when moving mail, rarely delete mail (which is a strong signal), and use forwarding as a gray area. The report recommends encoding these behavioral patterns into SOC scoring and detection workflows to reduce noise and prioritize genuinely suspicious accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.