Analytics BIOC Low

Exchange user mailbox forwarding

A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security
Licensed by:
Identity Threat Detection (ITDR)
Licensed by:
Email Security
Data source:
Office 365 Audit
ATT&CK tactics: Collection (TA0009) Exfiltration (TA0010)
ATT&CK techniques: Email Collection: Email Forwarding Rule (T1114.003) Automated Exfiltration (T1020) Email Collection (T1114)
Attacker's goals:

Leverage a compromised user account to modify a mailbox's settings to forward emails to an external recipient and collect sensitive information.

Investigative actions:

Look for signs that the user account and mailbox are compromised (e.g. abnormal logins, unusual activity). Check if the forwarding domain is an unknown external domain. Investigate the IP address associated with the rule. Follow further actions done by the account.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Exchange user mailbox forwarding by a delegate user Informational (parent: Low)
  • Suspicious Exchange user mailbox forwarding Medium (parent: Low)