Analytics BIOC Informational

Exchange email-hiding inbox rule

A user configured an Exchange inbox rule that may be used to hide emails.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
Licensed by:
Identity Threat Detection (ITDR)
Licensed by:
Email Security
Data source:
Office 365 Audit
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Hide Artifacts: Email Hiding Rules (T1564.008)
Attacker's goals:

Prevent an organization from warning users that they've been compromised (e.g. an internal spear-phishing campaign).

Investigative actions:

Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the rule keywords look suspicious. Investigate the IP address associated with the rule. Follow further actions done by the account. Check for a possible phishing campaign on the organization. Look for multiple instances of email hiding, which may be an indication of a larger campaign. Check if the user regularly configures inbox rules.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Possible BEC Exchange email-hiding inbox rule Medium (parent: Informational)
  • Suspicious Exchange email-hiding inbox rule Medium (parent: Informational)
  • Abnormal Exchange email-hiding inbox rule Low (parent: Informational)