Technique & Investigation of the Day · Educational, defensive guidance for authorized environments.
Why it matters
A mailbox rule can organize legitimate work or silently redirect important messages. Finding a forwarding rule does not establish that mail left the organization. Investigate configuration, authorization and actual delivery as separate questions.
HACK INVASION / VISUAL FIELD NOTES
Inbox rule investigations
Explore the diagram
Inbox rule investigations: investigation path. Preserve the changed configuration; Query related changes; Mailbox and inbox-rule change audit events with actor, target and parameters.; Validate the business explanation; Escalate; assess containment impact; Record the outcome
Select the image to open it separately for closer reading.
Required telemetry and evidence
- Mailbox and inbox-rule change audit events with actor, target and parameters.
- Current rule inventory, including hidden rules when supported by the authorized tooling.
- Message trace or equivalent delivery evidence and relevant mailbox access/sign-in records.
- Approved workflow documentation, destination ownership and mailbox delegation records.
Before drawing conclusions, record collection scope, retention and any missing fields. Keep sensitive evidence in approved internal systems.
Step-by-step investigation
1. Preserve the changed configuration
Capture rule conditions, actions, enabled state and target mailbox. Include forwarding, redirecting, deleting or moving messages. Avoid changing the rule while collecting the first evidence snapshot unless urgent response authority requires it.
2. Identify who changed what
Resolve the user or application that initiated the operation. Check delegations and administrator activity. A familiar display name is insufficient to establish the actor’s identity or authorization.
3. Query related changes
Review creation, modification and mailbox-forwarding operations around the event. Include later changes that could make the current state differ from the state when the alert fired.
4. Establish delivery scope
Use message trace and available access records to test whether matching messages were processed and delivered. A configured external destination may be blocked by policy. Do not equate a rule definition with confirmed information disclosure.
5. Validate the business explanation
Confirm destination ownership and workflow using trusted contacts. A legitimate support mailbox can explain routing; an unexplained external address and unrelated sign-in anomalies require deeper review.
6. Record the outcome
Separate unauthorized configuration, attempted forwarding and verified delivery in the report. Record affected time ranges and evidence limitations so downstream decisions do not assume more than the records show.
HACK INVASION / VISUAL FIELD NOTES
Inbox rule investigations
Explore the diagram
Inbox rule investigations: evidence checklist. Mailbox and inbox-rule change audit events with actor, target and parameters.; Current rule inventory, including hidden rules when supported by the authorized tooling.; Message trace or equivalent delivery evidence and relevant mailbox access/sign-in records.; Approved workflow documentation, destination ownership and mailbox delegation records.
Select the image to open it separately for closer reading.
Read-only investigation pseudocode
INPUT authorized mailbox-change and message-trace exports
SELECT rule or forwarding changes for the target mailbox
EXTRACT conditions, destination, actor and result
CORRELATE matching message delivery during the active interval
CLASSIFY configuration, attempted delivery and confirmed delivery separatelyTest and adapt: this is illustrative pseudocode, not executable vendor syntax or a tested production detector. Validate field semantics, time boundaries and results in an authorized environment. It does not change systems.
Legitimate activity versus suspicious activity
Rules used for ticketing, executive delegation and application notifications can be expected. Their scope should match the approved purpose. A broad rule affecting unrelated messages, silent deletion or an unowned destination weakens that explanation.
Tuning and false positives
Baseline rule purpose and destination ownership rather than rule names. Names can be misleading. Recheck exceptions after mailbox migrations and include both user rules and administrator forwarding settings in coverage.
Escalation, containment and documentation
Escalate confirmed unauthorized changes to the email-response owner. Disabling a rule, securing sessions and investigating related mailbox activity should follow the organization’s procedure. Preserve relevant delivery evidence before retention expires.
Close with an evidence-based disposition: explained activity, supported escalation or unresolved visibility gap. Include identifiers, times, source coverage, competing explanations and the response owner.
MITRE ATT&CK context
Email Forwarding Rule (T1114.003) is relevant when evidence supports adversarial email collection; a legitimate rule alone is not that technique.
Key takeaways
- Preserve the changed configuration: define the question before broadening the search.
- Validate the business explanation: corroborate the explanation with independent evidence.
- Keep the observed facts, assumptions and response decisions separate.
Related articles
- LOLBins threat hunting: process context and evidence correlation
- PSIRT preparation: communicating evidence and risk
- Explore the Knowledge Base
References
Original educational workflow and conceptual diagrams for Hack Invasion. Public documentation informs source-specific details; investigation decisions require local validation.
EmoticonEmoticon