Suspicious Outlook rules: high-fidelity patterns to watch for
ID: a5643151-84a7-54f8-a4ce-303cbaf16f78
STIX ID: report--a5643151-84a7-54f8-a4ce-303cbaf16f78
Feed Name: Expel Blog
This report examines how attackers manipulate Microsoft 365 Outlook inbox rules post‑compromise to hide notifications, forward MFA codes, exfiltrate documents, and facilitate lateral movement; it outlines detection approaches using New-InboxRule/Set-InboxRule audit events, lists high‑fidelity pattern indicators (suspicious rule names, actions like MarkAsRead/Delete/MoveToFolder, keywords such as "invoice"/"mfa"/"w2", and unusual folders), and shows real-world examples to help SOCs reduce false positives and tune alerts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
