Exchange mailbox group actions
| Operation | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all for M365-ExchangeItemGroup rules matching the RecordType but no specific Operation. | N | N |
| Hard | One or more messages were hard-deleted (purged from Recoverable Items) in a single bulk action; a common anti-forensics step. | Y | Y |
| Move | One or more messages were moved to another mailbox folder in a single bulk action. | Y | N |
| Move | One or more messages were moved to the Deleted Items folder in a single bulk action. | Y | Y |
| Soft | One or more messages were soft-deleted (moved to Recoverable Items) in a single bulk action. | Y | Y |
any: Exchange mailbox group actions (catch-all)
#Description
Catch-all for M365-ExchangeItemGroup rules matching the RecordType but no specific Operation.
References #
HardDelete
#Description
One or more messages were hard-deleted (purged from Recoverable Items) in a single bulk action; a common anti-forensics step.
Example Audit Record #
{
"AffectedItems": [
{
"Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLtyAAAJ",
"InternetMessageId": "<0100019309a1aab5-95864cc5-4c1c-48aa-b3cc-b37bb00a20e0-000000@email.amazonses.com>",
"ParentFolder": {
"Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
"Path": "\\Recoverable Items\\Deletions"
},
"Subject": " Profile Update Notification"
},
{
"Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLtzAAAJ",
"InternetMessageId": "<0100019309a0398e-62735e6e-dad4-43ec-883d-c24928f73406-000000@email.amazonses.com>",
"ParentFolder": {
"Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
"Path": "\\Recoverable Items\\Deletions"
},
"Subject": " OTP Notification"
},
{
"Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLt0AAAJ",
"InternetMessageId": "<01000193099f76f3-cef1c8ce-93f7-457d-a6ae-0891a911cafd-000000@email.amazonses.com>",
"ParentFolder": {
"Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
"Path": "\\Recoverable Items\\Deletions"
},
"Subject": " Password Change Notification"
},
{
"Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLt1AAAJ",
"InternetMessageId": "<01000193099ddd0d-6bb4da1d-4d21-4836-9e22-82f3a863f9b1-000000@email.amazonses.com>",
"ParentFolder": {
"Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
"Path": "\\Recoverable Items\\Deletions"
},
"Subject": " Account Recovery Notification"
},
{
"Attachments": "image (3540b); image (63465b)",
"Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLt2AAAJ",
"InternetMessageId": "<1477756244.25206.1731032231259@app131010.sjc201.ticketing-system.local>",
"ParentFolder": {
"Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
"Path": "\\Recoverable Items\\Deletions"
},
"Subject": "Incident receipt confirmation"
}
],
"AppAccessContext": {
"AADSessionId": "710d7677-bff8-4d01-ad48-824db2a6ffec",
"IssuedAtTime": "1970-01-01T00:00:00",
"UniqueTokenId": "eRFzqIsx-0mF9YdN0DHVAA"
},
"AppId": "00000002-0000-0ff1-ce00-000000000000",
"ClientAppId": "00000002-0000-0ff1-ce00-000000000000",
"ClientIP": "189.135.168.197",
"ClientIPAddress": "189.135.168.197",
"ClientInfoString": "Client=OWA;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 Edg/130.0.0.0;",
"CreationTime": "2025-01-16T03:41:38",
"CrossMailboxOperation": false,
"ExternalAccess": false,
"Folder": {
"Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
"Path": "\\Recoverable Items\\Deletions"
},
"Id": "ea2d5719-049c-45da-d3cc-08dcffa74029",
"InternalLogonType": 0,
"LogonType": 0,
"LogonUserSid": "S-1-5-21-7359471512-368169602-535915189-5038053",
"MailboxGuid": "51eb74b6-8b5e-4d97-a051-b69bd0b2cb77",
"MailboxOwnerSid": "S-1-5-21-7359471512-368169602-535915189-5038053",
"MailboxOwnerUPN": "victim_1@attack_range.lan",
"Operation": "HardDelete",
"OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
"OrganizationName": "attack_range.onmicrosoft.com",
"OriginatingServer": "SN6PR08MB4638 (15.20.4200.000)\r\n",
"RecordType": 3,
"ResultStatus": "Succeeded",
"SessionId": "710d7677-bff8-4d01-ad48-824db2a6ffec",
"UserId": "victim_1@attack_range.lan",
"UserKey": "10037FFE8CCD1F10",
"UserType": 0,
"Version": 1,
"Workload": "Exchange"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
m365::Folder.Path (splunk rule field) | in | \\recoverable items\\deletions | 4 rules | splunk |
m365::Folder.Path (splunk rule field) | in | \\sent items | 4 rules | splunk |
subject (splunk rule field) | in | *account recovery* | 2 rules | splunk |
subject (splunk rule field) | in | *banking* | 2 rules | splunk |
subject (splunk rule field) | in | *direct deposit* | 2 rules | splunk |
subject (splunk rule field) | in | *mfa * | 2 rules | splunk |
subject (splunk rule field) | in | *otp * | 2 rules | splunk |
subject (splunk rule field) | in | *passcode * | 2 rules | splunk |
subject (splunk rule field) | in | *password * | 2 rules | splunk |
subject (splunk rule field) | in | *pay-to* | 2 rules | splunk |
Status (splunk rule field) | eq | delivered | 1 rule | splunk |
count (splunk rule field) | gt | 50 | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1070, T1070.008, T1098, T1098.005↳ also matches MoveToDeletedItems, SoftDelete Splunk #
T1070, T1070.008, T1485T1070, T1070.008, T1114, T1114.001, T1485↳ also matches SoftDelete T1070, T1070.008, T1114, T1114.001, T1485
References #
Move
#Description
One or more messages were moved to another mailbox folder in a single bulk action.
Example Audit Record #
{
"CreationTime": "2019-11-26T23:15:43",
"Id": "*REDACTED*",
"Operation": "Move",
"OrganizationId": "*REDACTED*",
"RecordType": 3,
"ResultStatus": "Succeeded",
"UserKey": "*REDACTED*",
"UserType": 0,
"Version": 1,
"Workload": "Exchange",
"ClientIP": "*REDACTED*",
"UserId": "*REDACTED*",
"ClientIPAddress": "*REDACTED*",
"ClientInfoString": "*REDACTED*",
"ClientProcessName": "OUTLOOK.EXE",
"ClientVersion": "*REDACTED*",
"ExternalAccess": false,
"InternalLogonType": 0,
"LogonType": 0,
"LogonUserSid": "*REDACTED*",
"MailboxGuid": "*REDACTED*",
"MailboxOwnerSid": "*REDACTED*",
"MailboxOwnerUPN": "*REDACTED*",
"OrganizationName": "*REDACTED*",
"OriginatingServer": "*REDACTED*",
"SessionId": "*REDACTED*",
"AffectedItems": "*REDACTED*",
"CrossMailboxOperation": false,
"DestFolder": "*REDACTED*",
"Folder": "*REDACTED*"
}
References #
MoveToDeletedItems
#Description
One or more messages were moved to the Deleted Items folder in a single bulk action.
Example Audit Record #
{
"ActorInfoString": "Client=REST;python-requests/2.34.2[AppId=22222222-2222-2222-2222-222222222222];",
"AffectedItems": [
{
"Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAABt2NTyAAA7mE7t4w9CSqNKCbVE7kkMAABt2ebxAAAJ",
"InternetMessageId": "<SA1PR16MB4707133E40F11D3AF6535600A2F32@SA1PR16MB4707.namprd16.prod.outlook.com>",
"ParentFolder": {
"Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAABt2NTyAAAB",
"Path": "\\dw-harness-afc127f4"
},
"Subject": "dw-harness-afc127f4 move-test"
}
],
"AppAccessContext": {
"AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"APIId": "00000003-0000-0000-c000-000000000000",
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"IssuedAtTime": "2026-07-04T15:04:45Z",
"UniqueTokenId": "pO6tpCIhWEeDjtm8HsIAAA"
},
"AppId": "00000003-0000-0000-c000-000000000000",
"AuthType": "MSAuth1.0",
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"ClientIP": "203.0.113.10",
"ClientIPAddress": "203.0.113.10",
"ClientInfoString": "Client=REST;;",
"ClientRequestId": "d4a5cb36-15ed-46ee-8433-27d795927cc0",
"CreationTime": "2026-07-04T15:09:48Z",
"CrossMailboxOperation": false,
"DestFolder": {
"Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEKAAAB",
"Path": "\\Deleted Items"
},
"ExternalAccess": false,
"Folder": {
"Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAABt2NTyAAAB",
"Path": "\\dw-harness-afc127f4"
},
"HostAppId": "c999ed3e-27ae-4cb3-b3a2-46b056af63d3",
"Id": "35eccde5-64b4-4222-b4b6-08ded9de4a08",
"InternalLogonType": 0,
"LogonType": 0,
"LogonUserSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
"MailboxGuid": "2bc72b5a-02f0-45d2-97a2-5f0152098603",
"MailboxOwnerSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
"MailboxOwnerUPN": "adminuser@example.onmicrosoft.com",
"Operation": "MoveToDeletedItems",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"OrganizationName": "example.onmicrosoft.com",
"OriginatingServer": "SA1PR16MB4707 (15.20.4200.000)\r\n",
"RecordType": 3,
"ResultStatus": "Succeeded",
"SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"TokenObjectId": "11111111-1111-1111-1111-111111111111",
"TokenTenantId": "00000000-0000-0000-0000-000000000001",
"TokenType": "AadPft",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA",
"UserType": 0,
"Version": 1,
"Workload": "Exchange"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1070, T1070.008, T1098, T1098.005↳ also matches HardDelete, SoftDelete
References #
SoftDelete
#Description
One or more messages were soft-deleted (moved to Recoverable Items) in a single bulk action.
Example Audit Record #
{
"ActorInfoString": "Client=REST;python-requests/2.34.2[AppId=22222222-2222-2222-2222-222222222222];",
"AffectedItems": [
{
"Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAA7mE7t4w9CSqNKCbVE7kkMAABt2TLSAAAJ",
"InternetMessageId": "<SA1PR16MB4707170FA34E36D37A414A30A2F32@SA1PR16MB4707.namprd16.prod.outlook.com>",
"ParentFolder": {
"Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAAB",
"Path": "\\Drafts"
},
"Subject": "dw-harness-afc127f4 draft (updated)"
}
],
"AppAccessContext": {
"AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"APIId": "00000003-0000-0000-c000-000000000000",
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"IssuedAtTime": "2026-07-04T15:04:45Z",
"UniqueTokenId": "pO6tpCIhWEeDjtm8HsIAAA"
},
"AppId": "00000003-0000-0000-c000-000000000000",
"AuthType": "MSAuth1.0",
"ClientAppId": "22222222-2222-2222-2222-222222222222",
"ClientIP": "203.0.113.10",
"ClientIPAddress": "203.0.113.10",
"ClientInfoString": "Client=REST;;",
"ClientRequestId": "c6cddfac-0a5c-4f9f-a79a-df46d90d7516",
"CreationTime": "2026-07-04T15:09:47Z",
"CrossMailboxOperation": false,
"ExternalAccess": false,
"Folder": {
"Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAAB",
"Path": "\\Drafts"
},
"HostAppId": "c999ed3e-27ae-4cb3-b3a2-46b056af63d3",
"Id": "817e91e5-937b-4561-5fa3-08ded9de49aa",
"InternalLogonType": 0,
"LogonType": 0,
"LogonUserSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
"MailboxGuid": "2bc72b5a-02f0-45d2-97a2-5f0152098603",
"MailboxOwnerSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
"MailboxOwnerUPN": "adminuser@example.onmicrosoft.com",
"Operation": "SoftDelete",
"OrganizationId": "00000000-0000-0000-0000-000000000001",
"OrganizationName": "example.onmicrosoft.com",
"OriginatingServer": "SA1PR16MB4707 (15.20.4200.000)\r\n",
"RecordType": 3,
"ResultStatus": "Succeeded",
"SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
"TokenObjectId": "11111111-1111-1111-1111-111111111111",
"TokenTenantId": "00000000-0000-0000-0000-000000000001",
"TokenType": "AadPft",
"UserId": "adminuser@example.onmicrosoft.com",
"UserKey": "10000000AAAAAAAA",
"UserType": 0,
"Version": 1,
"Workload": "Exchange"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
m365::Folder.Path (splunk rule field) | in | \\recoverable items\\deletions | 1 rule | splunk |
m365::Folder.Path (splunk rule field) | in | \\sent items | 1 rule | splunk |
subject (splunk rule field) | in | *account recovery* | 1 rule | splunk |
subject (splunk rule field) | in | *banking* | 1 rule | splunk |
subject (splunk rule field) | in | *direct deposit* | 1 rule | splunk |
subject (splunk rule field) | in | *mfa * | 1 rule | splunk |
subject (splunk rule field) | in | *otp * | 1 rule | splunk |
subject (splunk rule field) | in | *passcode * | 1 rule | splunk |
subject (splunk rule field) | in | *password * | 1 rule | splunk |
subject (splunk rule field) | in | *pay-to* | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1070, T1070.008, T1098, T1098.005↳ also matches HardDelete, MoveToDeletedItems Splunk #
T1070, T1070.008, T1114, T1114.001, T1485↳ also matches HardDelete T1070, T1070.008, T1114, T1114.001, T1485↳ also matches HardDelete
References #
M365 audit records use different field names on each surface #
The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.
- Purview CSV export flattens each record to four columns (
CreationDate,UserIds,Operations,AuditData). The API field names live only inside theAuditDataJSON blob. Expand it withConvertFrom-Json. The wrapper columns are renamed too:CreationDatenotCreationTime,UserIdsnotUserId,OperationsnotOperation. - Sentinel's
OfficeActivitytable renames several fields and turns two integer enum columns into strings. The table below maps them.
| API JSON (event pages) | OfficeActivity column | Note |
|---|---|---|
Id | OfficeId | Renamed. |
Workload | OfficeWorkload | Renamed. |
ObjectId | OfficeObjectId | Renamed. |
CreationTime | TimeGenerated | Renamed. OfficeActivity has no CreationTime column. |
SiteUrl | Site_Url | Renamed (SharePoint family). |
RecordType | RecordType | Same name; the Int32 enum becomes its string enum name. |
UserType | UserType | Same name; the Int32 enum becomes a string. |
ClientIP | ClientIP, Client_IPAddress | Both columns present on OfficeActivity. |
Scope | (none) | No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob. |
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationId | same names | Unchanged. No _s / _d suffixes (a native table, not a custom log). |
Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.