Skip to content

Exchange Rules

11 detection rules in this category.

RuleSeverityMITRESource
Anti-phishing policy changedHighT1562.001AuditLog
Inbox rule with delete actionHighT1070.008AuditLog
Inbox rule with forwarding createdCriticalT1114.003AuditLog
Inbox rule with redirect createdCriticalT1114.003AuditLog
Journal rule createdCriticalT1114.003AuditLog
Mailbox forwarding enabledCriticalT1114.003AuditLog
Mailbox full access grantedHighT1098.002AuditLog
Safe attachments policy changedHighT1562.001AuditLog
Safe links policy changedHighT1562.001AuditLog
Send-as permission addedHighT1098.002AuditLog
Transport rule with forwarding createdCriticalT1114.003AuditLog

Anti-phishing policy changed

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1562.001 (Defense Evasion)

Anti-phishing policy modified

Conditions
  • Match: all
  • Operation Equals Set-AntiPhishPolicy

Inbox rule with delete action

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1070.008 (Defense Evasion)

Inbox rule deletes messages - possible evidence hiding

Conditions
  • Match: all
  • Operation Equals New-InboxRule
  • Parameters.DeleteMessage Exists

Inbox rule with forwarding created

PropertyValue
Severity🔴 Critical
SourceAuditLog
MITRET1114.003 (Collection)

Inbox rule forwards mail externally - BEC indicator

Conditions
  • Match: all
  • Operation Equals New-InboxRule
  • Parameters.ForwardTo Exists

Inbox rule with redirect created

PropertyValue
Severity🔴 Critical
SourceAuditLog
MITRET1114.003 (Collection)

Inbox rule redirects mail - BEC indicator

Conditions
  • Match: all
  • Operation Equals New-InboxRule
  • Parameters.RedirectTo Exists

Journal rule created

PropertyValue
Severity🔴 Critical
SourceAuditLog
MITRET1114.003 (Collection)

Email journaling rule created - mail being copied externally

Conditions
  • Match: all
  • Operation Equals New-JournalRule

Mailbox forwarding enabled

PropertyValue
Severity🔴 Critical
SourceAuditLog
MITRET1114.003 (Collection)

External mail forwarding configured - BEC indicator

Conditions
  • Match: all
  • Operation Equals Set-Mailbox
  • Parameters.ForwardingSmtpAddress Exists

Mailbox full access granted

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1098.002 (Persistence)

Full access permission granted to mailbox

Conditions
  • Match: all
  • Operation Equals Add-MailboxPermission
  • Parameters.AccessRights Contains FullAccess

Safe attachments policy changed

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1562.001 (Defense Evasion)

Safe Attachments policy modified

Conditions
  • Match: all
  • Operation Equals Set-SafeAttachmentPolicy

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1562.001 (Defense Evasion)

Safe Links policy modified

Conditions
  • Match: all
  • Operation Equals Set-SafeLinksPolicy

Send-as permission added

PropertyValue
Severity🟠 High
SourceAuditLog
MITRET1098.002 (Persistence)

Send-as permission granted - can impersonate sender

Conditions
  • Match: all
  • Operation Equals Add-RecipientPermission
  • Parameters.AccessRights Contains SendAs

Transport rule with forwarding created

PropertyValue
Severity🔴 Critical
SourceAuditLog
MITRET1114.003 (Collection)

Mail flow rule created that forwards or copies mail externally

Conditions
  • Match: all
  • Operation Equals New-TransportRule
  • undefined undefined