Skip to content
Playbook All on Content Hub Contains code

Mailbox forwarding-rule triage

Investigates suspicious mailbox forwarding rules: audit history, current rules and directory lookups.

@ftnt-dspilleMaintainer v1.0.0 Platform 7.4.0+ Published Sep 12, 2026
Download JSON · 34 KB

m365-forwarding-rule-triage.json

sha256:31b090c495b52eda06473d75caf37d0810439222fa9814df188a76d763327c64

Sanitized by the pipeline and shipped inactive. Follow the before turning it on.

Forwarding rules are a classic business-email-compromise persistence trick. This collection:

  1. Pulls forwarding/redirect-rule alerts from Microsoft Graph.
  2. For each alert, extracts the affected user, reads their current inbox rules and the Exchange audit trail.
  3. Classifies every forwarding destination against Active Directory: external or unresolved destinations are Critical, internal ones lower.

Three playbooks: an orchestrator, a per-alert worker and a destination classifier.

Something wrong with this item? Sign in to report

Report a problem

Sensitive data, copied content, broken imports, anything that shouldn't be here.

At least 10 characters. Please don't paste the sensitive value itself.0/1000