Exchange mailbox group actions

OperationDescriptionSampleRule
anyCatch-all for M365-ExchangeItemGroup rules matching the RecordType but no specific Operation.NN
HardDeleteOne or more messages were hard-deleted (purged from Recoverable Items) in a single bulk action; a common anti-forensics step.YY
MoveOne or more messages were moved to another mailbox folder in a single bulk action.YN
MoveToDeletedItemsOne or more messages were moved to the Deleted Items folder in a single bulk action.YY
SoftDeleteOne or more messages were soft-deleted (moved to Recoverable Items) in a single bulk action.YY

any: Exchange mailbox group actions (catch-all)

#
RecordType
ExchangeItemGroup

Description

Catch-all for M365-ExchangeItemGroup rules matching the RecordType but no specific Operation.

References #

HardDelete

#
RecordType
ExchangeItemGroup

Description

One or more messages were hard-deleted (purged from Recoverable Items) in a single bulk action; a common anti-forensics step.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation5 detection rulesSplunk
Workload5 detection rulesSplunk
Folder.Path4 detection rulesSplunk
event.action1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
o365.audit.AffectedItems.Subject1 detection ruleElastic

Example Audit Record #

{
  "AffectedItems": [
    {
      "Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLtyAAAJ",
      "InternetMessageId": "<0100019309a1aab5-95864cc5-4c1c-48aa-b3cc-b37bb00a20e0-000000@email.amazonses.com>",
      "ParentFolder": {
        "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
        "Path": "\\Recoverable Items\\Deletions"
      },
      "Subject": " Profile Update Notification"
    },
    {
      "Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLtzAAAJ",
      "InternetMessageId": "<0100019309a0398e-62735e6e-dad4-43ec-883d-c24928f73406-000000@email.amazonses.com>",
      "ParentFolder": {
        "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
        "Path": "\\Recoverable Items\\Deletions"
      },
      "Subject": " OTP Notification"
    },
    {
      "Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLt0AAAJ",
      "InternetMessageId": "<01000193099f76f3-cef1c8ce-93f7-457d-a6ae-0891a911cafd-000000@email.amazonses.com>",
      "ParentFolder": {
        "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
        "Path": "\\Recoverable Items\\Deletions"
      },
      "Subject": " Password Change Notification"
    },
    {
      "Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLt1AAAJ",
      "InternetMessageId": "<01000193099ddd0d-6bb4da1d-4d21-4836-9e22-82f3a863f9b1-000000@email.amazonses.com>",
      "ParentFolder": {
        "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
        "Path": "\\Recoverable Items\\Deletions"
      },
      "Subject": " Account Recovery Notification"
    },
    {
      "Attachments": "image (3540b); image (63465b)",
      "Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLt2AAAJ",
      "InternetMessageId": "<1477756244.25206.1731032231259@app131010.sjc201.ticketing-system.local>",
      "ParentFolder": {
        "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
        "Path": "\\Recoverable Items\\Deletions"
      },
      "Subject": "Incident receipt confirmation"
    }
  ],
  "AppAccessContext": {
    "AADSessionId": "710d7677-bff8-4d01-ad48-824db2a6ffec",
    "IssuedAtTime": "1970-01-01T00:00:00",
    "UniqueTokenId": "eRFzqIsx-0mF9YdN0DHVAA"
  },
  "AppId": "00000002-0000-0ff1-ce00-000000000000",
  "ClientAppId": "00000002-0000-0ff1-ce00-000000000000",
  "ClientIP": "189.135.168.197",
  "ClientIPAddress": "189.135.168.197",
  "ClientInfoString": "Client=OWA;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 Edg/130.0.0.0;",
  "CreationTime": "2025-01-16T03:41:38",
  "CrossMailboxOperation": false,
  "ExternalAccess": false,
  "Folder": {
    "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
    "Path": "\\Recoverable Items\\Deletions"
  },
  "Id": "ea2d5719-049c-45da-d3cc-08dcffa74029",
  "InternalLogonType": 0,
  "LogonType": 0,
  "LogonUserSid": "S-1-5-21-7359471512-368169602-535915189-5038053",
  "MailboxGuid": "51eb74b6-8b5e-4d97-a051-b69bd0b2cb77",
  "MailboxOwnerSid": "S-1-5-21-7359471512-368169602-535915189-5038053",
  "MailboxOwnerUPN": "victim_1@attack_range.lan",
  "Operation": "HardDelete",
  "OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "OrganizationName": "attack_range.onmicrosoft.com",
  "OriginatingServer": "SN6PR08MB4638 (15.20.4200.000)\r\n",
  "RecordType": 3,
  "ResultStatus": "Succeeded",
  "SessionId": "710d7677-bff8-4d01-ad48-824db2a6ffec",
  "UserId": "victim_1@attack_range.lan",
  "UserKey": "10037FFE8CCD1F10",
  "UserType": 0,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
m365::Folder.Path (splunk rule field)in\\recoverable items\\deletions4 rulessplunk
m365::Folder.Path (splunk rule field)in\\sent items4 rulessplunk
subject (splunk rule field)in*account recovery*2 rulessplunk
subject (splunk rule field)in*banking*2 rulessplunk
subject (splunk rule field)in*direct deposit*2 rulessplunk
subject (splunk rule field)in*mfa *2 rulessplunk
subject (splunk rule field)in*otp *2 rulessplunk
subject (splunk rule field)in*passcode *2 rulessplunk
subject (splunk rule field)in*password *2 rulessplunk
subject (splunk rule field)in*pay-to*2 rulessplunk
Status (splunk rule field)eqdelivered1 rulesplunk
count (splunk rule field)gt501 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange MFA Notification Email Deleted or Moved source low: Identifies when an MFA enrollment, registration, or security notification email is deleted or moved to deleted items in Microsoft 365 Exchange. Adversaries who compromise accounts and register their own MFA device often delete the notification emails to cover their tracks and prevent the legitimate user from noticing the unauthorized change. This technique is commonly observed in business email compromise (BEC) and account takeover attacks.T1070, T1070.008, T1098, T1098.005↳ also matches MoveToDeletedItems, SoftDelete

Splunk #

References #

Move

#
RecordType
ExchangeItemGroup

Description

One or more messages were moved to another mailbox folder in a single bulk action.

Example Audit Record #

{
  "CreationTime": "2019-11-26T23:15:43",
  "Id": "*REDACTED*",
  "Operation": "Move",
  "OrganizationId": "*REDACTED*",
  "RecordType": 3,
  "ResultStatus": "Succeeded",
  "UserKey": "*REDACTED*",
  "UserType": 0,
  "Version": 1,
  "Workload": "Exchange",
  "ClientIP": "*REDACTED*",
  "UserId": "*REDACTED*",
  "ClientIPAddress": "*REDACTED*",
  "ClientInfoString": "*REDACTED*",
  "ClientProcessName": "OUTLOOK.EXE",
  "ClientVersion": "*REDACTED*",
  "ExternalAccess": false,
  "InternalLogonType": 0,
  "LogonType": 0,
  "LogonUserSid": "*REDACTED*",
  "MailboxGuid": "*REDACTED*",
  "MailboxOwnerSid": "*REDACTED*",
  "MailboxOwnerUPN": "*REDACTED*",
  "OrganizationName": "*REDACTED*",
  "OriginatingServer": "*REDACTED*",
  "SessionId": "*REDACTED*",
  "AffectedItems": "*REDACTED*",
  "CrossMailboxOperation": false,
  "DestFolder": "*REDACTED*",
  "Folder": "*REDACTED*"
}

References #

MoveToDeletedItems

#
RecordType
ExchangeItemGroup

Description

One or more messages were moved to the Deleted Items folder in a single bulk action.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
event.action1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
o365.audit.AffectedItems.Subject1 detection ruleElastic

Example Audit Record #

{
  "ActorInfoString": "Client=REST;python-requests/2.34.2[AppId=22222222-2222-2222-2222-222222222222];",
  "AffectedItems": [
    {
      "Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAABt2NTyAAA7mE7t4w9CSqNKCbVE7kkMAABt2ebxAAAJ",
      "InternetMessageId": "<SA1PR16MB4707133E40F11D3AF6535600A2F32@SA1PR16MB4707.namprd16.prod.outlook.com>",
      "ParentFolder": {
        "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAABt2NTyAAAB",
        "Path": "\\dw-harness-afc127f4"
      },
      "Subject": "dw-harness-afc127f4 move-test"
    }
  ],
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppId": "22222222-2222-2222-2222-222222222222",
    "IssuedAtTime": "2026-07-04T15:04:45Z",
    "UniqueTokenId": "pO6tpCIhWEeDjtm8HsIAAA"
  },
  "AppId": "00000003-0000-0000-c000-000000000000",
  "AuthType": "MSAuth1.0",
  "ClientAppId": "22222222-2222-2222-2222-222222222222",
  "ClientIP": "203.0.113.10",
  "ClientIPAddress": "203.0.113.10",
  "ClientInfoString": "Client=REST;;",
  "ClientRequestId": "d4a5cb36-15ed-46ee-8433-27d795927cc0",
  "CreationTime": "2026-07-04T15:09:48Z",
  "CrossMailboxOperation": false,
  "DestFolder": {
    "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEKAAAB",
    "Path": "\\Deleted Items"
  },
  "ExternalAccess": false,
  "Folder": {
    "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAABt2NTyAAAB",
    "Path": "\\dw-harness-afc127f4"
  },
  "HostAppId": "c999ed3e-27ae-4cb3-b3a2-46b056af63d3",
  "Id": "35eccde5-64b4-4222-b4b6-08ded9de4a08",
  "InternalLogonType": 0,
  "LogonType": 0,
  "LogonUserSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
  "MailboxGuid": "2bc72b5a-02f0-45d2-97a2-5f0152098603",
  "MailboxOwnerSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
  "MailboxOwnerUPN": "adminuser@example.onmicrosoft.com",
  "Operation": "MoveToDeletedItems",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.20.4200.000)\r\n",
  "RecordType": 3,
  "ResultStatus": "Succeeded",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "TokenType": "AadPft",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA",
  "UserType": 0,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)contains2-step1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)contains2fa1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsauthenticator1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsdevice activate1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsdevice added1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsdevice change1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsdevice configure1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsdevice enroll1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsdevice register1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsdevice setup1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsdevice update1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsdevice verify1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsfactor activate1 ruleelastic
o365.audit.AffectedItems.Subject (elastic rule field)containsfactor added1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange MFA Notification Email Deleted or Moved source low: Identifies when an MFA enrollment, registration, or security notification email is deleted or moved to deleted items in Microsoft 365 Exchange. Adversaries who compromise accounts and register their own MFA device often delete the notification emails to cover their tracks and prevent the legitimate user from noticing the unauthorized change. This technique is commonly observed in business email compromise (BEC) and account takeover attacks.T1070, T1070.008, T1098, T1098.005↳ also matches HardDelete, SoftDelete

References #

SoftDelete

#
RecordType
ExchangeItemGroup

Description

One or more messages were soft-deleted (moved to Recoverable Items) in a single bulk action.

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
Operation2 detection rulesSplunk
Workload2 detection rulesSplunk
event.action1 detection ruleElastic
event.outcome1 detection ruleElastic
event.provider1 detection ruleElastic
Folder.Path1 detection ruleSplunk
o365.audit.AffectedItems.Subject1 detection ruleElastic

Example Audit Record #

{
  "ActorInfoString": "Client=REST;python-requests/2.34.2[AppId=22222222-2222-2222-2222-222222222222];",
  "AffectedItems": [
    {
      "Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAA7mE7t4w9CSqNKCbVE7kkMAABt2TLSAAAJ",
      "InternetMessageId": "<SA1PR16MB4707170FA34E36D37A414A30A2F32@SA1PR16MB4707.namprd16.prod.outlook.com>",
      "ParentFolder": {
        "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAAB",
        "Path": "\\Drafts"
      },
      "Subject": "dw-harness-afc127f4 draft (updated)"
    }
  ],
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppId": "22222222-2222-2222-2222-222222222222",
    "IssuedAtTime": "2026-07-04T15:04:45Z",
    "UniqueTokenId": "pO6tpCIhWEeDjtm8HsIAAA"
  },
  "AppId": "00000003-0000-0000-c000-000000000000",
  "AuthType": "MSAuth1.0",
  "ClientAppId": "22222222-2222-2222-2222-222222222222",
  "ClientIP": "203.0.113.10",
  "ClientIPAddress": "203.0.113.10",
  "ClientInfoString": "Client=REST;;",
  "ClientRequestId": "c6cddfac-0a5c-4f9f-a79a-df46d90d7516",
  "CreationTime": "2026-07-04T15:09:47Z",
  "CrossMailboxOperation": false,
  "ExternalAccess": false,
  "Folder": {
    "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAAB",
    "Path": "\\Drafts"
  },
  "HostAppId": "c999ed3e-27ae-4cb3-b3a2-46b056af63d3",
  "Id": "817e91e5-937b-4561-5fa3-08ded9de49aa",
  "InternalLogonType": 0,
  "LogonType": 0,
  "LogonUserSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
  "MailboxGuid": "2bc72b5a-02f0-45d2-97a2-5f0152098603",
  "MailboxOwnerSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
  "MailboxOwnerUPN": "adminuser@example.onmicrosoft.com",
  "Operation": "SoftDelete",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.20.4200.000)\r\n",
  "RecordType": 3,
  "ResultStatus": "Succeeded",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "TokenType": "AadPft",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA",
  "UserType": 0,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
m365::Folder.Path (splunk rule field)in\\recoverable items\\deletions1 rulesplunk
m365::Folder.Path (splunk rule field)in\\sent items1 rulesplunk
subject (splunk rule field)in*account recovery*1 rulesplunk
subject (splunk rule field)in*banking*1 rulesplunk
subject (splunk rule field)in*direct deposit*1 rulesplunk
subject (splunk rule field)in*mfa *1 rulesplunk
subject (splunk rule field)in*otp *1 rulesplunk
subject (splunk rule field)in*passcode *1 rulesplunk
subject (splunk rule field)in*password *1 rulesplunk
subject (splunk rule field)in*pay-to*1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange MFA Notification Email Deleted or Moved source low: Identifies when an MFA enrollment, registration, or security notification email is deleted or moved to deleted items in Microsoft 365 Exchange. Adversaries who compromise accounts and register their own MFA device often delete the notification emails to cover their tracks and prevent the legitimate user from noticing the unauthorized change. This technique is commonly observed in business email compromise (BEC) and account takeover attacks.T1070, T1070.008, T1098, T1098.005↳ also matches HardDelete, MoveToDeletedItems

Splunk #

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.