Loading interactive filters…
1200KM / detection
T1114.003 Email Forwarding Rule — Detection Rules
Detection workspace for T1114.003 Email Forwarding Rule: 2 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
Atlas deterministic concepts
T1114.003 Email Forwarding Rule
MATCH(forwarding_rule_created) AND destination_domain NOT_IN approved_domains -> ALERT
Anomaly models
Email forwarding rule created — T1114.003 Email Forwarding Rule
Comparison unit: mailbox-destination relationship.
Expected behavior: forwarding is absent or targets a small stable destination set.
Deviation: first-seen external destination or rule created outside the user's normal workflow.
ATT&CK analytic guidance
Creation of inbox rules via PowerShell (New-InboxRule) or transport rules using Exchange cmdlets. Correlates user behavior, cmdlet usage, and rule properties.
Creation or modification of Apple Mail rules by accessing plist files or GUI automation (AppleScript).
Creation of email forwarding/redirect rules in Exchange Online via New-InboxRule or transport rule cmdlets, including auto-forwarding address field usage.
Modification of Thunderbird message filters file or execution of CLI tools (e.g., formail/procmail) that alter .forward behavior.
Connected ecosystem references
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.