Payroll Pirate - Malicious Inbox Rule for Email Hiding

Detects the creation or modification of inbox rules via PowerShell, specifically targeting cmdlets commonly used by attackers to hide phishing indicator emails, security alerts, or C2 communications by moving or deleting them into folders like Junk, Deleted Items, or Archive. The rule monitors for both direct usage on the endpoint and remote administration patterns via Exchange Online/EWS remoting.