1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1114.003 Email Forwarding Rule — Detection Rules

Detection workspace for T1114.003 Email Forwarding Rule: 2 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1114.003 Email Forwarding Rule

MATCH(forwarding_rule_created) AND destination_domain NOT_IN approved_domains -> ALERT

Anomaly models

ATT&CK analytic guidance

DET0576 Email Forwarding Rule Abuse Detection Across Platforms

AN1589 Analytic 1589

Creation of inbox rules via PowerShell (New-InboxRule) or transport rules using Exchange cmdlets. Correlates user behavior, cmdlet usage, and rule properties.

AN1590 Analytic 1590

Creation or modification of Apple Mail rules by accessing plist files or GUI automation (AppleScript).

AN1591 Analytic 1591

Creation of email forwarding/redirect rules in Exchange Online via New-InboxRule or transport rule cmdlets, including auto-forwarding address field usage.

AN1592 Analytic 1592

Modification of Thunderbird message filters file or execution of CLI tools (e.g., formail/procmail) that alter .forward behavior.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1114.003 simulation workspace

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.