Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0192 — Detection Strategy for Email Hiding Rules
DET0192

Detection Strategy for Email Hiding Rules

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0551 Analytic 0551
Windows

Suspicious creation or modification of inbox rules through PowerShell (New-InboxRule, Set-InboxRule) to automatically delete, move, or hide emails. Defender perspective: unusual rule activity correlated with mailbox access and filtering patterns.

WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 m365:unified New-InboxRule or Set-InboxRule events recorded in Exchange Online
[SuspiciousKeywords] Keywords like 'phish', 'malware', 'suspicious' used in inbox rules to hide emails.
[UserContext] Scope mailbox monitoring to high-value users such as executives or admins.
AN0552 Analytic 0552
macOS

Alterations to plist configuration files (RulesActiveState.plist, SyncedRules.plist, UnsyncedRules.plist, MessageRules.plist) that define email hiding or filtering rules. Defender perspective: unexpected changes in these files associated with Mail.app processes.

macos:unifiedlog Modifications to Mail.app plist files controlling message rules macos:unifiedlog Mail.app executing with parameters updating rules state
[WatchedPlistFiles] Adjust to monitor only rule-related plist files relevant to the environment.
AN0553 Analytic 0553
Linux

Rule manipulation through local email clients (e.g., Evolution, Thunderbird) or server-side filtering scripts (e.g., sieve) creating conditions to move or discard emails with security-related keywords.

auditd:SYSCALL execve calls modifying local mail filter configuration files ApplicationLog:MailServer Unexpected additions of sieve rules or filtering directives
[MailServerLogs] Customize based on mail server software (Postfix, Dovecot, Exim).
AN0554 Analytic 0554
Office Suite

Suspicious rule creation within Outlook or Exchange clients, including auto-move or delete conditions tied to incident or security alert keywords. Defender perspective: correlation between missing inbound emails and newly added mailbox rules.

m365:unified Transport rule or inbox rule creation events
[RuleScope] Decide whether to monitor individual mailbox rules, org-wide transport rules, or both.

Detected Techniques

1

Details

MITRE ID
DET0192
STIX ID
x-mitre-detection-strategy--54aaab69-62fb-4d40-b2e0-0d07594353ed
Analytics
4
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.