Check Inbox Rules for a Hacker in Microsoft 365
How attackers use inbox rules and forwarding in a BEC, how to find them in the Unified Audit Log and with Get-InboxRule, and how to tell them from real ones.
This tool is not affiliated with, endorsed by or sponsored by Microsoft Corporation. Microsoft 365, Microsoft Entra ID, Exchange Online and Microsoft Purview are trademarks of the Microsoft group of companies. Other names are trademarks of their respective owners.
Series
4 posts in this series. Read them in order or jump to any one.
How attackers use inbox rules and forwarding in a BEC, how to find them in the Unified Audit Log and with Get-InboxRule, and how to tell them from real ones.
How AiTM phishing steals Microsoft 365 sessions despite MFA, and how to detect the token replay in Entra ID sign-in logs and the Unified Audit Log.
How to spot an illicit OAuth consent grant in the Unified Audit Log and Entra audit logs, which scopes matter, and how to remove the app's access.
Reading MailItemsAccessed records in a BEC case: Sync vs Bind, InternetMessageId, throttling, licensing, and telling the attacker's reads from the user's.
How attackers use inbox rules and forwarding in a BEC, how to find them in the Unified Audit Log and with Get-InboxRule, and how to tell them from real ones.
How AiTM phishing steals Microsoft 365 sessions despite MFA, and how to detect the token replay in Entra ID sign-in logs and the Unified Audit Log.
How to spot an illicit OAuth consent grant in the Unified Audit Log and Entra audit logs, which scopes matter, and how to remove the app's access.
Reading MailItemsAccessed records in a BEC case: Sync vs Bind, InternetMessageId, throttling, licensing, and telling the attacker's reads from the user's.