top of page
Adversarial Email forward rules
Affects:

Severity:
HIGH
Productivity Impact:
LOW
Fix Estimate:
10 minutes
Automatically protected by:

Research:
Summary:
Adversaries set up forwarding rules on your users email inboxes to exfiltrate sensitive data and as a form of insurance in case they lose access to their victim’s email account.
Remediation details
Check forwarding reports
Navigate to https://admin.exchange.microsoft.com
Click on Reports > Mail Flow
Click on Auto forwarded message report
Review all forwarding rules for suspicious email recipients
bottom of page