OAuth App Mail Permission Grant Followed by Inbox Rule Creation

Detects a sequence where an OAuth application is granted 'Mail.ReadWrite' or 'MailboxSettings.ReadWrite' permissions, followed shortly thereafter (within 4 hours) by the creation or modification of an Inbox Rule by that same application within the same mailbox. This pattern is indicative of a persistence mechanism where an adversary uses elevated OAuth permissions to manipulate mailbox mail flow rules for stealth or exfiltration.