Glossary
Inbox rule
A mailbox rule that automatically moves, deletes, marks or forwards incoming messages; attackers use them in BEC to hide replies and exfiltrate mail.
An inbox rule is a server-side rule on an Exchange Online mailbox that acts on incoming messages: move to a folder, mark as read, delete, forward or redirect. Users create them in Outlook; attackers create them after taking over an account, to hide replies (move to RSS Feeds or Archive, mark read, delete) and to keep receiving copies (forward to an outside address). MITRE ATT&CK tracks these as Email Hiding Rules (T1564.008) and Email Forwarding Rule (T1114.003).
In the Unified Audit Log they appear as New-InboxRule, Set-InboxRule, Enable-InboxRule (Outlook on the web, PowerShell) or UpdateInboxRules (Outlook desktop). The current rules, including hidden ones, are listed with Get-InboxRule -IncludeHidden.
Details: malicious inbox rules and forwarding.