M365 Inbox Rule Moving Emails to Hidden or Rarely Checked Folders

Detects the creation or modification of inbox rules that move messages to rarely checked folders like Archive, RSS Subscriptions, Conversation History, Junk Email, or Deleted Items. This is a common post-exploitation technique used to hide fraudulent communications (BEC, payroll fraud) or suppress security alerts, MFA notifications, and password reset emails from the victim. Approximately 10% of compromised accounts have malicious mailbox rules created shortly after initial access.