Email Forwarding Rule Created to External Address

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies inbox forwarding rules created to redirect or forward email to an external address outside the organization, which may indicate an attacker using cloud app permissions to establish persistent mail collection for long-term data exfiltration.

Attribute Value
Type Hunting Query
Solution Hybrid Attack - Cloud & Identity
ID e8c2d54d-908e-4e20-b930-8dfb865d0b71
Tactics Collection, Exfiltration
Techniques T1020.001, T1567
Required Connectors MicrosoftCloudAppSecurity
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity