Microsoft Defender XDR
Incidents and response

Alert classification for suspicious inbox manipulation rules

In brief

The playbook now more explicitly covers true and false positives, compromised accounts, rules without filters, activity before suspicious rules were created, and related alerts. Metadata and the publication date were also updated.

What Defender admins need to know

Security teams get clearer guidance for investigating suspicious inbox rules and following remediation steps. No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Alert classification for suspicious inbox manipulation rules description: Alert classificationInvestigate alerts for suspicious inbox manipulation rules to review the alertsrules, determine whether they are true or false positives, and takefollow recommended actions to remediate the attack and protect your network.remediation steps for compromised accounts. ms.service: defender-xdr ms.author: guywild author: guywi-ms ms.collection:

  • m365-security
  • tier2 ms.custom: admindeeplinkDEFENDER, msecd-doc-authoring-10141016 ms.topic: how-to ms.date: 06/15/07/02/2026 appliesto:
  • Microsoft Defender XDR ai-usage: ai-assisted

Threat actors can use compromised user accounts for many malicious purposes including reading emails in a user's inbox, creating inbox rules to forward emails to external accounts, deleting traces, and sending phishing mails. Malicious inbox rules are common during business email compromise (BEC) and phishing campaigns and it's important to monitor for them consistently.

This playbook helps you investigate any incident related to suspicious inbox manipulation rules configured by attackers and take recommended actions to remediate the attack and protect your network. This playbook is for security teams, including security operations center (SOC) analysts and IT administrators who review, investigate, and grade the alerts. You can quickly grade alerts as either a true positive (TP) or a false positive (TP)(FP) and take recommended actions for the TP alerts to remediate the attack.

The results of using this playbook are:

If there are filtering by keywords, then check whether the keywords seem suspicious to you (common scenarios are to filter emails related to the attacker activities, such as "phish," "spam," and "do not reply," among others).

If there is no filter at all, ita rule with no filter might be suspicious as well.

  • Destination folder

4. Investigate suspicious activity by the user prior to creating the rules

You can review all user activities before the suspicious inbox rules were created, check for indicators of compromise, and investigate user actions that seem suspicious.

For instance, for multiple failed logins, examine:

  • Incident

    Check whether the investigated alert is associated with other alerts that indicate an incident. If so, then check whether the incident contains other true positive alerts.

Advanced hunting queries

[!INCLUDE Microsoft Defender XDR rebranding]