
Rule Info
Name
Suspicious Inbox Manipulation Rules
Author
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
Description
Detects suspicious rules that delete or move messages or folders are set on a user's inbox.
Date
2023-09-03 00:00:00
Modified
None
Id
ceb55fd0-726e-4656-bf4e-b585b7f7d572
Tags
attack.t1140 attack.defense_evasion DEMO
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Mark Morowczynski
Merge PR #4423 from @MarkMorow - Add Azure AD Identity Protection Rules
2023-09-06