| name | detecting-email-forwarding-rules-attack |
| description | Detect malicious email forwarding rules created by adversaries to maintain persistent access to email communications for intelligence collection and BEC attacks. Use when detecting malicious email forwarding rules created by adversaries to maintain. |
| domain | cybersecurity |
| tags | ["threat-hunting","mitre-attack","email-forwarding","persistence","bec","t1114","proactive-detection"] |
| subdomain | threat-hunting |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| d3fend_techniques | ["Restore Object","Restore Configuration","Application Configuration Hardening","Application Hardening","Disable Remote Access"] |
| nist_csf | ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"] |
Detecting Email Forwarding Rules Attack
Overview
Cybersecurity skill for detecting email forwarding rules attack. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"detecting email forwarding rules attack"
-
"When proactively hunting for indicators of detecting email forwarding rules atta"
-
"After threat intelligence indicates active campaigns using these techniques"
-
"During incident response to scope compromise related to these techniques"
-
When proactively hunting for indicators of detecting email forwarding rules attack in the environment
-
After threat intelligence indicates active campaigns using these techniques
-
During incident response to scope compromise related to these techniques
-
When EDR or SIEM alerts trigger on related indicators
-
During periodic security assessments and purple team exercises
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) k, v IOC_PATTERNS.items()}