Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies inbox forwarding rules created to redirect or forward email to an external address outside the organization, which may indicate an attacker using cloud app permissions to establish persistent mail collection for long-term data exfiltration.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Hybrid Attack - Cloud & Identity |
| ID | e8c2d54d-908e-4e20-b930-8dfb865d0b71 |
| Tactics | Collection, Exfiltration |
| Techniques | T1020.001, T1567 |
| Required Connectors | MicrosoftCloudAppSecurity |
| Source | View on GitHub |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity