Techniques › T1114 › T1114.003
T1114.003 Email Forwarding Rule
collection — Linux, macOS, Office Suite, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
6
Sigma rules tagged attack.t1114.003
0
KEV CVEs mapped here
<p>Adversaries may setup email forwarding rules to collect sensitive information. Adversaries may abuse email forwarding rules to monitor the activities of a victim, steal information, and further gain intelligence on the victim or the victim’s organization to use as part of further exploits or operations. Furthermore, email forwarding rules can allow adversaries to maintain persistent access to victim's emails even after compromised credentials are reset by administrators. Most email clients allow users to create inbox rules for various email functions, including forwarding to a different recipient. These rules may be created through a local email application, a web interface, or by command-line interface. Messages can be forwarded to internal or external recipients, and there are no restrictions limiting the extent of this rule. Administrators may also create forwarding rules for user accounts with the same considerations and outcomes.</p><p>Any user or administrator within the organization (or adversary with valid credentials) can create rules to automatically forward all received messages to another recipient, forward emails to different locations based on the sender, and more. Adversaries may also hide the rule by making use of the Microsoft Messaging API (MAPI) to modify the rule properties, making it hidden and not visible from Outlook, OWA or most Exchange Administration tools.</p><p>In some environments, administrators may be able to enable email forwarding rules that operate organization-wide rather than on individual inboxes. For example, Microsoft Exchange supports transport rules that evaluate all mail an organization receives against user-specified conditions, then performs a user-specified action on mail that adheres to those conditions. Adversaries that abuse such features may be able to enable forwarding on all or specific mail an organization receives.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0576 Email Forwarding Rule Abuse Detection Across Platforms v1.0
AN1589 WindowsCreation of inbox rules via PowerShell (New-InboxRule) or transport rules using Exchange cmdlets. Correlates user behavior, cmdlet usage, and rule properties.Tunable:
UserContextTimeWindowTargetMailboxAN1590 macOSCreation or modification of Apple Mail rules by accessing plist files or GUI automation (AppleScript).fs:plist_monitoring/Users/*/Library/Mail/V*/MailData/RulesActiveState.plist→ DC0061 File ModificationTunable:RuleFilePathScriptTriggerAN1591 Office SuiteCreation of email forwarding/redirect rules in Exchange Online via New-InboxRule or transport rule cmdlets, including auto-forwarding address field usage.Tunable:ForwardingSMTPAddressActorIdAN1592 LinuxModification of Thunderbird message filters file or execution of CLI tools (e.g., formail/procmail) that alter .forward behavior.Tunable:.forwardPathExecContext
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1114.003
Author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
· 2026-02-10 · logsource: product=windows category=ps_script · 04580eed-e1d6-426b-a570-f6e64a4577f7
Detects inbox rule creation or update via ExchangePowerShell cmdlet, a technique commonly observed in Business Email Compromise (BEC) attacks to hide emails.
The usage of inbox rules can be a sign of a compromised mailbox, where an attacker is attempting to evade detections by suppressing or redirecting incoming emails.
Analysts should review these rules in context, validate whether they reflect normal user behavior, and correlate with other indicators such as unusual login activity or recent mailbox rule modifications.
Author: Nasreddine Bencherchali (Nextron Systems), Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
· 2026-03-01 · logsource: product=windows category=ps_script · 0c7686d5-c74e-4292-b224-2a08e956ebc4
Detects email forwarding or redirecting activity via ExchangePowerShell Cmdlet
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-03 · logsource: product=azure service=riskdetection · 27e4f1d6-ae72-4ea0-8a67-77a73a289c3d
Indicates suspicious rules such as an inbox rule that forwards a copy of all emails to an external address
Author: Tom kluter
· 2026-04-28 · logsource: product=gcp service=google_workspace.login · 2a0bb2dd-eb5f-4517-8cb9-404f8ba764a5
Detects automatic email forwarding to external domains in Google Workspace, which may indicate data leakage or misuse.
Author: RedCanary Team (idea), Harjot Singh @cyb3rjy0t
· 2023-10-11 (modified 2024-11-17) · logsource: product=m365 service=audit · c726e007-2cd0-4a55-abfb-79730fbedee5
Detects email forwarding or redirecting activity in O365 Audit logs.
Author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
· 2026-01-09 · logsource: product=m365 service=audit · d3577be1-42c9-44a7-b56e-2e8de97349d3
Detects inbox rule creation or update via O365 Audit logs, a technique commonly observed in Business Email Compromise (BEC) attacks to hide emails.
The usage of inbox rules can be a sign of a compromised mailbox, where an attacker is attempting to evade detections by suppressing or redirecting incoming emails.
Analysts should review these rules in context, validate whether they reflect normal user behavior, and correlate with other indicators such as unusual login activity or recent mailbox rule modifications.
Rules tagged at the parent level (attack.t1114) 4
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Sorina Ionescu
· 2022-02-08 (modified 2022-11-17) · logsource: product=m365 service=threat_management · 18b88d08-d73e-4f21-bc25-4b9892a4fdd0
Alert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content
Author: Florian Roth (Nextron Systems)
· 2017-05-31 (modified 2022-10-09) · logsource: product=windows service=security · 24549159-ac1b-479c-8175-d42aea947cae
This events that are generated when using the hacktool Ruler by Sensepost
Author: FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems)
· 2021-03-03 (modified 2023-03-24) · logsource: product=windows category=process_creation · 25676e10-2121-446e-80a4-71ff8506af47
Detects adding and using Exchange PowerShell snap-ins to export mailbox data. As seen used by HAFNIUM and APT27
Author: Nikita Khalimonenkov
· 2022-11-17 · logsource: product=m365 service=threat_management · 6897cd82-6664-11ed-9022-0242ac120002
Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.