M365 Malicious Mailbox Rule Abuse

Detects the creation or modification of Microsoft 365 Exchange inbox rules that exhibit characteristics of malicious behavior, such as using trivial or blank names, moving items to rarely-monitored folders (e.g., 'Conversation History', 'RSS Feeds'), or containing keywords related to phishing, credential harvesting, or financial fraud.