Playbook All on Content Hub Contains code
Mailbox forwarding-rule triage
Investigates suspicious mailbox forwarding rules: audit history, current rules and directory lookups.
@ftnt-dspilleMaintainer v1.0.0 Platform 7.4.0+ Published Sep 12, 2026
Download JSON · 34 KB
m365-forwarding-rule-triage.json
sha256:31b090c495b52eda06473d75caf37d0810439222fa9814df188a76d763327c64
Sanitized by the pipeline and shipped inactive. Follow the before turning it on.
Forwarding rules are a classic business-email-compromise persistence trick. This collection:
- Pulls forwarding/redirect-rule alerts from Microsoft Graph.
- For each alert, extracts the affected user, reads their current inbox rules and the Exchange audit trail.
- Classifies every forwarding destination against Active Directory: external or unresolved destinations are Critical, internal ones lower.
Three playbooks: an orchestrator, a per-alert worker and a destination classifier.
Something wrong with this item? Sign in to report