detecting-email-forwarding-rules-attack

Installation
SKILL.md

Detecting Email Forwarding Rules Attack

When to Use

  • When proactively hunting for indicators of detecting email forwarding rules attack in the environment
  • After threat intelligence indicates active campaigns using these techniques
  • During incident response to scope compromise related to these techniques
  • When EDR or SIEM alerts trigger on related indicators
  • During periodic security assessments and purple team exercises

Prerequisites

  • EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
  • SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
  • Sysmon deployed with comprehensive configuration
  • Windows Security Event Log forwarding enabled
  • Threat intelligence feeds for IOC correlation

Workflow

Related skills
Installs
14
GitHub Stars
6.2K
First Seen
Mar 16, 2026