Identity Management (Entra ID)

Stealth Exchange Rules: Hunt & Remediate — Akuity SOC

5 min read Akuity SOC · Delphisoft Deutschland

Detect post-AiTM email forwarding (T1114.003) in Exchange Online. KQL Advanced Hunting query and instant 1-click SOAR remediation with Akuity SOC.

The Anatomy of Silent Persistence Post Session Theft

When an attacker successfully bypasses Multi-Factor Authentication via an Adversary-in-the-Middle (AiTM) reverse proxy, their priority is rarely noisy privilege escalation. Instead, to maintain silent surveillance over high-value communications without triggering anomalous sign-in alerts in Microsoft Entra ID, adversaries implement MITRE ATT&CK T1114.003 (Email Forwarding Rule).

Once connected to Exchange Online, the attacker injects an inbox rule specifically designed to hide tracks from the genuine user. The rule pairs an exfiltration mechanic (forwarding incoming emails containing sensitive terms like "wire transfer", "invoice", "audit", or "credentials" to an external throwaway mailbox) with an evasive action: marking the email as read, deleting it, or routing it directly into Deleted Items or Hidden Folders.

Native Blind Spots in Standard Detection

While Defender for Office 365 provides default tenant-wide alerts for external forwarding rules, SOC teams frequently encounter critical gaps:

  • Alert Latency: Compliance and Exchange audit events can exhibit processing delays ranging from 15 to 90 minutes before bubbling up to the unified incident queue.
  • Disconnected Context: Standard alerts flag the rule creation in isolation, failing to correlate the source IP with the AiTM session token compromise observed minutes earlier in sign-in telemetry.
  • Triage Noise: Legitimate business users configure sorting rules regularly, burying exfiltration indicators beneath false positives.

Proactive Threat Hunting with Advanced Hunting (KQL)

To pinpoint stealth forwarding rules created across your tenant in the last 24 hours, run the following query in Advanced Hunting (KQL) inside Microsoft Defender:

CloudAppEvents
| where Timestamp > ago(24h) and Application == "Microsoft Exchange Online"
| where ActionType in~ ("New-InboxRule", "Set-InboxRule")
| mv-expand Param = RawEventData.Parameters
| extend PName = tostring(Param.Name), PValue = tostring(Param.Value)
| summarize Parameters = make_bag(pack(PName, PValue)) by ReportId, Timestamp, AccountDisplayName, IPAddress, UserAgent
| extend ForwardTo = tostring(coalesce(Parameters.ForwardTo, Parameters.RedirectTo)),
         HasStealthAction = (Parameters.MarkAsRead == "True" or isnotempty(Parameters.MoveToFolder) or Parameters.DeleteMessage == "True"),
         RuleName = tostring(Parameters.Name)
| where isnotempty(ForwardTo) and HasStealthAction
| extend RecipientDomain = tostring(split(ForwardTo, "@")[1])
| where not(RecipientDomain in~ ("domaine-interne.fr", "partenaire-certifie.com"))
| project Timestamp, AccountDisplayName, IPAddress, RuleName, ForwardTo, RecipientDomain, UserAgent

This query specifically filters for external redirects combined with stealth modifiers (mark as read, move, or delete), eliminating the noise of mundane user configurations.

Rapid Remediation via Akuity SOC SOAR

Manually connecting with Exchange Online PowerShell during an active breach introduces unacceptable dwell time. Akuity SOC accelerates incident triage and containment into seconds:

  • Analyst Fatigue Mitigation: The in-app Akuity SOC AI assistant decodes rule parameters in under 2 seconds, extracting IOCs securely without data leakage to unmanaged external web services.
  • 1-Click SOAR Response: Directly from the evidence timeline, the analyst triggers revokeSessions() to purge the adversary's hijacked session, executes confirmUserCompromised() in Microsoft Entra ID, and launches blockIocOnTenant() to neutralize adversary endpoints across the tenant.
  • Zero-Trust Governance: All critical remediation commands require MFA AAL2 step-up verification and are captured in an immutable audit trail aligned with NIS 2 and SOC 2 Type II compliance standards.

Secure Your Exchange Environment in Minutes

Stop malicious forwarding rules before exfiltrated data impacts your organization. Experience agentless detection and automated response with Akuity SOC.

Start Your 14-Day Free Trial (No Credit Card Required)

Technical FAQ

Does disabling external auto-forwarding completely prevent this attack vector?

Outbound anti-spam policies blocking auto-forwarding mitigate basic rules. However, sophisticated attackers exploit RedirectTo actions or target misconfigured internal mailbox delegations to circumvent standard transport blocks if Conditional Access is not tightly enforced.

Does revoking active user sessions automatically delete the malicious rule?

No. Calling revokeSessions() invalidates active refresh tokens and OAuth sessions in Microsoft Entra ID, kicking out the threat actor. However, the inbox rule remains running on Exchange Online server-side until explicitly deleted via the Microsoft Graph API or PowerShell, a step automated by Akuity SOC playbooks.

Related Solution Page

Plateforme SOC & SOAR Microsoft

Automatisez votre détection et votre réponse aux incidents avec Akuity SOC.

Discover the complete solution