LoFP LoFP / actual mailbox rules that are moving items based on their workflow.

Techniques

Sample rules

Suspicious Inbox Manipulation Rules

Description

Detects suspicious rules that delete or move messages or folders are set on a user’s inbox.

Detection logic

condition: selection
selection:
  riskEventType: mcasSuspiciousInboxManipulationRules