Skip to content

<<< Hide Navigation Hide TOC >>>

Suspicious Inbox Forwarding (6c220477-0b5b-4b25-bb90-66183b4089e8)

Detects when a Microsoft Cloud App Security reported suspicious email forwarding rules, for example, if a user created an inbox rule that forwards a copy of all emails to an external address.

Galaxy ColorsSigma-Rule...Attack Pat...
Rows: 1
Loading extensions...
Collapse filters
Use the filters above each column to filter and limit table data. Advanced searches can be performed by using the following operators:
<, <=, >, >=, =, *, !, {, }, ||,&&, [empty], [nonempty], rgx:
Learn more

TableFilter v0.7.2

https://www.tablefilter.com/
©2015-2025 Max Guglielmi
?
Cluster A Galaxy A Cluster B Galaxy B Level
Suspicious Inbox Forwarding (6c220477-0b5b-4b25-bb90-66183b4089e8) Sigma-Rules Automated Exfiltration - T1020 (774a3188-6ba9-4dc4-879d-d54ee48a5ce9) Attack Pattern 1