Skip to content
  • Home
  • Modern Workplace
  • Blog
  • Knowledge Base
  • Home
  • Modern Workplace
  • Blog
  • Knowledge Base

© 2019

Posts in 27 January 2024

AzureModern Workplace
January 27, 2024

Microsoft Sentinel: Malicious Inbox Rule V2

This improved Sentinel Analytics Rule can be used to detect malicious Inbox Rules used by threat actors to hide invoice fraud activity. I've used the Inbox rule currently available as a template within Sentinel, and modified it to alert on Outlook rules I encountered in the wild.
5
read more

This is a success preview text.

This is a error preview text.

Recent Posts

  • The G-Door: Microsoft 365 & the risk of unmanaged Google Doc accounts
  • Automating Azure SQL Maintenance with Azure Automation
  • Malware Analysis – Shortcuts in zip file
  • Identifying Duplicate Files Across All SharePoint Sites Using PowerShell
  • How to Guard Against Token Theft for Microsoft 365
  • IT-Boost TOTP Secret Exposure
  • Balance Device Wave Groups for granular Intune deployments
  • Platform Upgrade: Microsoft 365 agentless CSS phishing protection
  • Exchange Online External Forwarding Risk – quarantine bypass
  • Microsoft Sentinel: Malicious Inbox Rule V2
© 2025 Prof-IT Services | Privacy Policy