Attackers Create Inbox Rules. They Don't Rewrite Yours. by Stephan Hoehl
ID: 0622d4be-0e47-5d81-9f12-852b9c76a28e
STIX ID: report--0622d4be-0e47-5d81-9f12-852b9c76a28e
Feed Name: Vectra AI Blog
Threat Score
This Vectra AI analysis describes how threat actors abuse Microsoft 365 mailbox rules following account takeover: attackers typically create new, minimally named rules, prefer default folders when moving mail, rarely delete mail (which is a strong signal), and use forwarding as a gray area. The report recommends encoding these behavioral patterns into SOC scoring and detection workflows to reduce noise and prioritize genuinely suspicious accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
