The Anatomy of Silent Persistence Post Session Theft
When an attacker successfully bypasses Multi-Factor Authentication via an Adversary-in-the-Middle (AiTM) reverse proxy, their priority is rarely noisy privilege escalation. Instead, to maintain silent surveillance over high-value communications without triggering anomalous sign-in alerts in Microsoft Entra ID, adversaries implement MITRE ATT&CK T1114.003 (Email Forwarding Rule).
Once connected to Exchange Online, the attacker injects an inbox rule specifically designed to hide tracks from the genuine user. The rule pairs an exfiltration mechanic (forwarding incoming emails containing sensitive terms like "wire transfer", "invoice", "audit", or "credentials" to an external throwaway mailbox) with an evasive action: marking the email as read, deleting it, or routing it directly into Deleted Items or Hidden Folders.
Native Blind Spots in Standard Detection
While Defender for Office 365 provides default tenant-wide alerts for external forwarding rules, SOC teams frequently encounter critical gaps:
- Alert Latency: Compliance and Exchange audit events can exhibit processing delays ranging from 15 to 90 minutes before bubbling up to the unified incident queue.
- Disconnected Context: Standard alerts flag the rule creation in isolation, failing to correlate the source IP with the AiTM session token compromise observed minutes earlier in sign-in telemetry.
- Triage Noise: Legitimate business users configure sorting rules regularly, burying exfiltration indicators beneath false positives.
Proactive Threat Hunting with Advanced Hunting (KQL)
To pinpoint stealth forwarding rules created across your tenant in the last 24 hours, run the following query in Advanced Hunting (KQL) inside Microsoft Defender:
CloudAppEvents
| where Timestamp > ago(24h) and Application == "Microsoft Exchange Online"
| where ActionType in~ ("New-InboxRule", "Set-InboxRule")
| mv-expand Param = RawEventData.Parameters
| extend PName = tostring(Param.Name), PValue = tostring(Param.Value)
| summarize Parameters = make_bag(pack(PName, PValue)) by ReportId, Timestamp, AccountDisplayName, IPAddress, UserAgent
| extend ForwardTo = tostring(coalesce(Parameters.ForwardTo, Parameters.RedirectTo)),
HasStealthAction = (Parameters.MarkAsRead == "True" or isnotempty(Parameters.MoveToFolder) or Parameters.DeleteMessage == "True"),
RuleName = tostring(Parameters.Name)
| where isnotempty(ForwardTo) and HasStealthAction
| extend RecipientDomain = tostring(split(ForwardTo, "@")[1])
| where not(RecipientDomain in~ ("domaine-interne.fr", "partenaire-certifie.com"))
| project Timestamp, AccountDisplayName, IPAddress, RuleName, ForwardTo, RecipientDomain, UserAgentThis query specifically filters for external redirects combined with stealth modifiers (mark as read, move, or delete), eliminating the noise of mundane user configurations.
Rapid Remediation via Akuity SOC SOAR
Manually connecting with Exchange Online PowerShell during an active breach introduces unacceptable dwell time. Akuity SOC accelerates incident triage and containment into seconds:
- Analyst Fatigue Mitigation: The in-app Akuity SOC AI assistant decodes rule parameters in under 2 seconds, extracting IOCs securely without data leakage to unmanaged external web services.
- 1-Click SOAR Response: Directly from the evidence timeline,
the analyst triggers
revokeSessions()to purge the adversary's hijacked session, executesconfirmUserCompromised()in Microsoft Entra ID, and launchesblockIocOnTenant()to neutralize adversary endpoints across the tenant. - Zero-Trust Governance: All critical remediation commands require MFA AAL2 step-up verification and are captured in an immutable audit trail aligned with NIS 2 and SOC 2 Type II compliance standards.
Secure Your Exchange Environment in Minutes
Stop malicious forwarding rules before exfiltrated data impacts your organization. Experience agentless detection and automated response with Akuity SOC.
Technical FAQ
Does disabling external auto-forwarding completely prevent this attack vector?
Outbound anti-spam policies blocking auto-forwarding mitigate basic rules.
However, sophisticated attackers exploit RedirectTo actions or
target misconfigured internal mailbox delegations to circumvent standard transport
blocks if Conditional Access is not tightly enforced.
Does revoking active user sessions automatically delete the malicious rule?
No. Calling revokeSessions() invalidates active refresh tokens
and OAuth sessions in Microsoft Entra ID, kicking out the threat actor. However,
the inbox rule remains running on Exchange Online server-side until explicitly
deleted via the Microsoft Graph API or PowerShell, a step automated by Akuity
SOC playbooks.