Skip to content

This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.

Glossary

Inbox rule

A mailbox rule that automatically moves, deletes, marks or forwards incoming messages; attackers use them in BEC to hide replies and exfiltrate mail.

An inbox rule is a server-side rule on an Exchange Online mailbox that acts on incoming messages: move to a folder, mark as read, delete, forward or redirect. Users create them in Outlook; attackers create them after taking over an account, to hide replies (move to RSS Feeds or Archive, mark read, delete) and to keep receiving copies (forward to an outside address). MITRE ATT&CK tracks these as Email Hiding Rules (T1564.008) and Email Forwarding Rule (T1114.003).

In the Unified Audit Log they appear as New-InboxRule, Set-InboxRule, Enable-InboxRule (Outlook on the web, PowerShell) or UpdateInboxRules (Outlook desktop). The current rules, including hidden ones, are listed with Get-InboxRule -IncludeHidden.

Details: malicious inbox rules and forwarding.