Skip to content
Hack InvasionCybersecurity Knowledge Hub

Suspicious Inbox Rules: Investigating Intent, Scope and Delivery

Technique & Investigation of the Day · Educational, defensive guidance for authorized environments.

Why it matters

A mailbox rule can organize legitimate work or silently redirect important messages. Finding a forwarding rule does not establish that mail left the organization. Investigate configuration, authorization and actual delivery as separate questions.

HACK INVASION / VISUAL FIELD NOTES

Inbox rule investigations

Inbox rule investigations: investigation path. Preserve the changed configuration; Query related changes; Mailbox and inbox-rule change audit events with actor, target and parameters.; Validate the business explanation; Escalate; assess containment impact; Record the outcome
Original conceptual investigation workflow. No real customer data is shown.
Explore the diagram

Inbox rule investigations: investigation path. Preserve the changed configuration; Query related changes; Mailbox and inbox-rule change audit events with actor, target and parameters.; Validate the business explanation; Escalate; assess containment impact; Record the outcome

Select the image to open it separately for closer reading.

Required telemetry and evidence

  • Mailbox and inbox-rule change audit events with actor, target and parameters.
  • Current rule inventory, including hidden rules when supported by the authorized tooling.
  • Message trace or equivalent delivery evidence and relevant mailbox access/sign-in records.
  • Approved workflow documentation, destination ownership and mailbox delegation records.

Before drawing conclusions, record collection scope, retention and any missing fields. Keep sensitive evidence in approved internal systems.

Step-by-step investigation

1. Preserve the changed configuration

Capture rule conditions, actions, enabled state and target mailbox. Include forwarding, redirecting, deleting or moving messages. Avoid changing the rule while collecting the first evidence snapshot unless urgent response authority requires it.

2. Identify who changed what

Resolve the user or application that initiated the operation. Check delegations and administrator activity. A familiar display name is insufficient to establish the actor’s identity or authorization.

3. Query related changes

Review creation, modification and mailbox-forwarding operations around the event. Include later changes that could make the current state differ from the state when the alert fired.

4. Establish delivery scope

Use message trace and available access records to test whether matching messages were processed and delivered. A configured external destination may be blocked by policy. Do not equate a rule definition with confirmed information disclosure.

5. Validate the business explanation

Confirm destination ownership and workflow using trusted contacts. A legitimate support mailbox can explain routing; an unexplained external address and unrelated sign-in anomalies require deeper review.

6. Record the outcome

Separate unauthorized configuration, attempted forwarding and verified delivery in the report. Record affected time ranges and evidence limitations so downstream decisions do not assume more than the records show.

HACK INVASION / VISUAL FIELD NOTES

Inbox rule investigations

Inbox rule investigations: evidence checklist. Mailbox and inbox-rule change audit events with actor, target and parameters.; Current rule inventory, including hidden rules when supported by the authorized tooling.; Message trace or equivalent delivery evidence and relevant mailbox access/sign-in records.; Approved workflow documentation, destination ownership and mailbox delegation records.
Original conceptual evidence checklist. No real customer data is shown.
Explore the diagram

Inbox rule investigations: evidence checklist. Mailbox and inbox-rule change audit events with actor, target and parameters.; Current rule inventory, including hidden rules when supported by the authorized tooling.; Message trace or equivalent delivery evidence and relevant mailbox access/sign-in records.; Approved workflow documentation, destination ownership and mailbox delegation records.

Select the image to open it separately for closer reading.

Read-only investigation pseudocode

INPUT authorized mailbox-change and message-trace exports
SELECT rule or forwarding changes for the target mailbox
EXTRACT conditions, destination, actor and result
CORRELATE matching message delivery during the active interval
CLASSIFY configuration, attempted delivery and confirmed delivery separately

Test and adapt: this is illustrative pseudocode, not executable vendor syntax or a tested production detector. Validate field semantics, time boundaries and results in an authorized environment. It does not change systems.

Legitimate activity versus suspicious activity

Rules used for ticketing, executive delegation and application notifications can be expected. Their scope should match the approved purpose. A broad rule affecting unrelated messages, silent deletion or an unowned destination weakens that explanation.

Tuning and false positives

Baseline rule purpose and destination ownership rather than rule names. Names can be misleading. Recheck exceptions after mailbox migrations and include both user rules and administrator forwarding settings in coverage.

Escalation, containment and documentation

Escalate confirmed unauthorized changes to the email-response owner. Disabling a rule, securing sessions and investigating related mailbox activity should follow the organization’s procedure. Preserve relevant delivery evidence before retention expires.

Close with an evidence-based disposition: explained activity, supported escalation or unresolved visibility gap. Include identifiers, times, source coverage, competing explanations and the response owner.

MITRE ATT&CK context

Email Forwarding Rule (T1114.003) is relevant when evidence supports adversarial email collection; a legitimate rule alone is not that technique.

Key takeaways

  • Preserve the changed configuration: define the question before broadening the search.
  • Validate the business explanation: corroborate the explanation with independent evidence.
  • Keep the observed facts, assumptions and response decisions separate.

Related articles

References

Original educational workflow and conceptual diagrams for Hack Invasion. Public documentation informs source-specific details; investigation decisions require local validation.

Latest


EmoticonEmoticon