ALT-2418 · Microsoft 365
Suspicious inbox rule created to delete security mail
A rule was created that moves messages containing 'security' or 'phishing' to RSS Feeds and marks read.
mediumNewconfidence 61% · 1969-12-31 22:51:00Z · rule DET-0076 Malicious Inbox Rule
Detection summary
A rule was created that moves messages containing 'security' or 'phishing' to RSS Feeds and marks read.
- Affected host
- SRV-WEB-02
- Affected user
- a.pratama
- Source IP
- 10.20.7.43
- Detection rule
- DET-0076 Malicious Inbox Rule
- Log source
- Microsoft 365
- Assignee
- S. Hartono
Recommended actions
- Remove the inbox rule
- Review mailbox audit log
- Check for related BEC indicators
Analyst decision
Triage checklist
- 1. Confirm the detection logic matched genuine activity.
- 2. Check user and asset context for expected behaviour.
- 3. Pivot on host, user, IP and hash in the Log Explorer.
- 4. Enrich IOCs with threat intelligence.
- 5. Set a verdict and record your reasoning.