ALT-2430 · Microsoft 365
Suspicious inbox rule created to delete security mail
A rule was created that moves messages containing 'security' or 'phishing' to RSS Feeds and marks read.
mediumNewconfidence 96% · 1969-12-31 18:54:00Z · rule DET-0076 Malicious Inbox Rule
Detection summary
A rule was created that moves messages containing 'security' or 'phishing' to RSS Feeds and marks read.
- Affected host
- SRV-WEB-02
- Affected user
- l.ferreira
- Source IP
- 10.20.4.172
- Detection rule
- DET-0076 Malicious Inbox Rule
- Log source
- Microsoft 365
- Assignee
- You
Recommended actions
- Remove the inbox rule
- Review mailbox audit log
- Check for related BEC indicators
Analyst decision
Triage checklist
- 1. Confirm the detection logic matched genuine activity.
- 2. Check user and asset context for expected behaviour.
- 3. Pivot on host, user, IP and hash in the Log Explorer.
- 4. Enrich IOCs with threat intelligence.
- 5. Set a verdict and record your reasoning.