1. Prerequisites
- Suspected or confirmed mailbox compromise
- Access to email administration platform
- Access to audit logs
- Access to affected mailbox
2. Step-by-Step Instructions
-
Identify Mailbox in Scope
- Confirm affected mailbox.
-
Review Inbox Rules
- Identify:
- Auto-delete rules
- Move rules
- Forwarding rules
- Hidden rules
- Identify:
-
Review Mail Forwarding Configuration
- Review:
- Internal forwarding
- External forwarding
- Forwarding destinations
- Review:
-
Review Delegated Access
- Identify:
- Delegates
- Shared mailbox access
- Administrative assignments
- Identify:
-
Review Mail Flow Configuration
- Review:
- Transport rules
- Routing changes
- Forwarding policies
- Review:
-
Review Rule Creation Activity
- Determine:
- Creation time
- Creator account
- Modification history
- Determine:
-
Identify Suspicious Destinations
- Assess:
- External addresses
- Unknown domains
- Attacker-controlled infrastructure
- Assess:
-
Assess Data Exposure
- Determine:
- Data potentially forwarded
- Duration of forwarding
- Impacted communications
- Determine:
-
Document Findings
- Record all identified rules and forwarding activity.
-
Escalate and Hand Off
- Escalate findings for containment and recovery.
- Update the incident record.
3. Post-Action
- Preserve mailbox configuration artifacts.
- Document findings and exposure assessment.
- Attach evidence to the incident record.
Contributor
Vishal Thakur
GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
