JELAJAH SOC
YO

ALT-2406 · Microsoft 365

Suspicious inbox rule created to delete security mail

A rule was created that moves messages containing 'security' or 'phishing' to RSS Feeds and marks read.

Back to queue
mediumNewconfidence 79% · 1969-12-31 18:19:00Z · rule DET-0076 Malicious Inbox RuleLinked to INC-1042

Detection summary

A rule was created that moves messages containing 'security' or 'phishing' to RSS Feeds and marks read.

Affected host
SRV-WEB-02
Affected user
r.wijaya
Source IP
10.20.15.62
Detection rule
DET-0076 Malicious Inbox Rule
Log source
Microsoft 365
Assignee
Unassigned

Recommended actions

  • Remove the inbox rule
  • Review mailbox audit log
  • Check for related BEC indicators

Analyst decision

Triage checklist

  • 1. Confirm the detection logic matched genuine activity.
  • 2. Check user and asset context for expected behaviour.
  • 3. Pivot on host, user, IP and hash in the Log Explorer.
  • 4. Enrich IOCs with threat intelligence.
  • 5. Set a verdict and record your reasoning.