Malicious 'Patroit' Email Compliance Rule Creation

Detects the creation or modification of an email compliance or forwarding rule containing the specific typo "Patroit". This indicator is associated with the UNC6508 threat actor's data exfiltration activities via silently BCC-forwarding sensitive emails.