Exchange mailbox group actions

OperationDescriptionSampleRule
anyCatch-all for M365-ExchangeItemGroup rules matching the RecordType but no specific Operation.NN
HardDeleteOne or more messages were hard-deleted (purged from Recoverable Items) in a single bulk action; a common anti-forensics step.YY
MoveOne or more messages were moved to another mailbox folder in a single bulk action.YN
MoveToDeletedItemsOne or more messages were moved to the Deleted Items folder in a single bulk action.YY
SoftDeleteOne or more messages were soft-deleted (moved to Recoverable Items) in a single bulk action.YY

any: Exchange mailbox group actions (catch-all)

#
RecordType
ExchangeItemGroup

Description

Catch-all for M365-ExchangeItemGroup rules matching the RecordType but no specific Operation.

References #

HardDelete

#
RecordType
ExchangeItemGroup

Description

One or more messages were hard-deleted (purged from Recoverable Items) in a single bulk action; a common anti-forensics step.

Example Audit Record #

{
  "AffectedItems": [
    {
      "Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLtyAAAJ",
      "InternetMessageId": "<0100019309a1aab5-95864cc5-4c1c-48aa-b3cc-b37bb00a20e0-000000@email.amazonses.com>",
      "ParentFolder": {
        "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
        "Path": "\\Recoverable Items\\Deletions"
      },
      "Subject": " Profile Update Notification"
    },
    {
      "Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLtzAAAJ",
      "InternetMessageId": "<0100019309a0398e-62735e6e-dad4-43ec-883d-c24928f73406-000000@email.amazonses.com>",
      "ParentFolder": {
        "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
        "Path": "\\Recoverable Items\\Deletions"
      },
      "Subject": " OTP Notification"
    },
    {
      "Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLt0AAAJ",
      "InternetMessageId": "<01000193099f76f3-cef1c8ce-93f7-457d-a6ae-0891a911cafd-000000@email.amazonses.com>",
      "ParentFolder": {
        "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
        "Path": "\\Recoverable Items\\Deletions"
      },
      "Subject": " Password Change Notification"
    },
    {
      "Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLt1AAAJ",
      "InternetMessageId": "<01000193099ddd0d-6bb4da1d-4d21-4836-9e22-82f3a863f9b1-000000@email.amazonses.com>",
      "ParentFolder": {
        "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
        "Path": "\\Recoverable Items\\Deletions"
      },
      "Subject": " Account Recovery Notification"
    },
    {
      "Attachments": "image (3540b); image (63465b)",
      "Id": "RgAAAAA+yhqHkUHNQrg0+gADdFUvBwBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAFzIXi2IUPRISo8vEZM/upAAXJHLt2AAAJ",
      "InternetMessageId": "<1477756244.25206.1731032231259@app131010.sjc201.ticketing-system.local>",
      "ParentFolder": {
        "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
        "Path": "\\Recoverable Items\\Deletions"
      },
      "Subject": "Incident receipt confirmation"
    }
  ],
  "AppAccessContext": {
    "AADSessionId": "710d7677-bff8-4d01-ad48-824db2a6ffec",
    "IssuedAtTime": "1970-01-01T00:00:00",
    "UniqueTokenId": "eRFzqIsx-0mF9YdN0DHVAA"
  },
  "AppId": "00000002-0000-0ff1-ce00-000000000000",
  "ClientAppId": "00000002-0000-0ff1-ce00-000000000000",
  "ClientIP": "189.135.168.197",
  "ClientIPAddress": "189.135.168.197",
  "ClientInfoString": "Client=OWA;Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 Edg/130.0.0.0;",
  "CreationTime": "2025-01-16T03:41:38",
  "CrossMailboxOperation": false,
  "ExternalAccess": false,
  "Folder": {
    "Id": "LgAAAAA+yhqHkUHNQrg0+gADdFUvAQBGbZqJmK0XS6cbI8Sqvv4UAAAAAfLmAAAB",
    "Path": "\\Recoverable Items\\Deletions"
  },
  "Id": "ea2d5719-049c-45da-d3cc-08dcffa74029",
  "InternalLogonType": 0,
  "LogonType": 0,
  "LogonUserSid": "S-1-5-21-7359471512-368169602-535915189-5038053",
  "MailboxGuid": "51eb74b6-8b5e-4d97-a051-b69bd0b2cb77",
  "MailboxOwnerSid": "S-1-5-21-7359471512-368169602-535915189-5038053",
  "MailboxOwnerUPN": "victim_1@attack_range.lan",
  "Operation": "HardDelete",
  "OrganizationId": "6915b1e0-b081-4829-8866-f1a3e883a9ae",
  "OrganizationName": "attack_range.onmicrosoft.com",
  "OriginatingServer": "SN6PR08MB4638 (15.20.4200.000)\r\n",
  "RecordType": 3,
  "ResultStatus": "Succeeded",
  "SessionId": "710d7677-bff8-4d01-ad48-824db2a6ffec",
  "UserId": "victim_1@attack_range.lan",
  "UserKey": "10037FFE8CCD1F10",
  "UserType": 0,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
m365::Folder.Path (splunk rule field)in\\recoverable items\\deletions4 rulessplunk
m365::Folder.Path (splunk rule field)in\\sent items4 rulessplunk
subject (splunk rule field)in*account recovery*2 rulessplunk
subject (splunk rule field)in*banking*2 rulessplunk
subject (splunk rule field)in*direct deposit*2 rulessplunk
subject (splunk rule field)in*mfa *2 rulessplunk
subject (splunk rule field)in*otp *2 rulessplunk
subject (splunk rule field)in*passcode *2 rulessplunk
subject (splunk rule field)in*password *2 rulessplunk
subject (splunk rule field)in*pay-to*2 rulessplunk
Status (splunk rule field)eqdelivered1 rulesplunk
count (splunk rule field)gt501 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange MFA Notification Email Deleted or Moved source low: Identifies when an MFA enrollment, registration, or security notification email is deleted or moved to deleted items in Microsoft 365 Exchange. Adversaries who compromise accounts and register their own MFA device often delete the notification emails to cover their tracks and prevent the legitimate user from noticing the unauthorized change. This technique is commonly observed in business email compromise (BEC) and account takeover attacks.T1070, T1070.008, T1098, T1098.005↳ also matches MoveToDeletedItems, SoftDelete

Splunk #

References #

Move

#
RecordType
ExchangeItemGroup

Description

One or more messages were moved to another mailbox folder in a single bulk action.

Example Audit Record #

{
  "CreationTime": "2019-11-26T23:15:43",
  "Id": "*REDACTED*",
  "Operation": "Move",
  "OrganizationId": "*REDACTED*",
  "RecordType": 3,
  "ResultStatus": "Succeeded",
  "UserKey": "*REDACTED*",
  "UserType": 0,
  "Version": 1,
  "Workload": "Exchange",
  "ClientIP": "*REDACTED*",
  "UserId": "*REDACTED*",
  "ClientIPAddress": "*REDACTED*",
  "ClientInfoString": "*REDACTED*",
  "ClientProcessName": "OUTLOOK.EXE",
  "ClientVersion": "*REDACTED*",
  "ExternalAccess": false,
  "InternalLogonType": 0,
  "LogonType": 0,
  "LogonUserSid": "*REDACTED*",
  "MailboxGuid": "*REDACTED*",
  "MailboxOwnerSid": "*REDACTED*",
  "MailboxOwnerUPN": "*REDACTED*",
  "OrganizationName": "*REDACTED*",
  "OriginatingServer": "*REDACTED*",
  "SessionId": "*REDACTED*",
  "AffectedItems": "*REDACTED*",
  "CrossMailboxOperation": false,
  "DestFolder": "*REDACTED*",
  "Folder": "*REDACTED*"
}

References #

MoveToDeletedItems

#
RecordType
ExchangeItemGroup

Description

One or more messages were moved to the Deleted Items folder in a single bulk action.

Example Audit Record #

{
  "ActorInfoString": "Client=REST;python-requests/2.34.2[AppId=22222222-2222-2222-2222-222222222222];",
  "AffectedItems": [
    {
      "Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAABt2NTyAAA7mE7t4w9CSqNKCbVE7kkMAABt2ebxAAAJ",
      "InternetMessageId": "<SA1PR16MB4707133E40F11D3AF6535600A2F32@SA1PR16MB4707.namprd16.prod.outlook.com>",
      "ParentFolder": {
        "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAABt2NTyAAAB",
        "Path": "\\dw-harness-afc127f4"
      },
      "Subject": "dw-harness-afc127f4 move-test"
    }
  ],
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppId": "22222222-2222-2222-2222-222222222222",
    "IssuedAtTime": "2026-07-04T15:04:45Z",
    "UniqueTokenId": "pO6tpCIhWEeDjtm8HsIAAA"
  },
  "AppId": "00000003-0000-0000-c000-000000000000",
  "AuthType": "MSAuth1.0",
  "ClientAppId": "22222222-2222-2222-2222-222222222222",
  "ClientIP": "203.0.113.10",
  "ClientIPAddress": "203.0.113.10",
  "ClientInfoString": "Client=REST;;",
  "ClientRequestId": "d4a5cb36-15ed-46ee-8433-27d795927cc0",
  "CreationTime": "2026-07-04T15:09:48Z",
  "CrossMailboxOperation": false,
  "DestFolder": {
    "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEKAAAB",
    "Path": "\\Deleted Items"
  },
  "ExternalAccess": false,
  "Folder": {
    "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAABt2NTyAAAB",
    "Path": "\\dw-harness-afc127f4"
  },
  "HostAppId": "c999ed3e-27ae-4cb3-b3a2-46b056af63d3",
  "Id": "35eccde5-64b4-4222-b4b6-08ded9de4a08",
  "InternalLogonType": 0,
  "LogonType": 0,
  "LogonUserSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
  "MailboxGuid": "2bc72b5a-02f0-45d2-97a2-5f0152098603",
  "MailboxOwnerSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
  "MailboxOwnerUPN": "adminuser@example.onmicrosoft.com",
  "Operation": "MoveToDeletedItems",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.20.4200.000)\r\n",
  "RecordType": 3,
  "ResultStatus": "Succeeded",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "TokenType": "AadPft",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA",
  "UserType": 0,
  "Version": 1,
  "Workload": "Exchange"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange MFA Notification Email Deleted or Moved source low: Identifies when an MFA enrollment, registration, or security notification email is deleted or moved to deleted items in Microsoft 365 Exchange. Adversaries who compromise accounts and register their own MFA device often delete the notification emails to cover their tracks and prevent the legitimate user from noticing the unauthorized change. This technique is commonly observed in business email compromise (BEC) and account takeover attacks.T1070, T1070.008, T1098, T1098.005↳ also matches HardDelete, SoftDelete

References #

SoftDelete

#
RecordType
ExchangeItemGroup

Description

One or more messages were soft-deleted (moved to Recoverable Items) in a single bulk action.

Example Audit Record #

{
  "ActorInfoString": "Client=REST;python-requests/2.34.2[AppId=22222222-2222-2222-2222-222222222222];",
  "AffectedItems": [
    {
      "Id": "RgAAAAAXRoXzP5fNR6PyEo/HqixABwA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAA7mE7t4w9CSqNKCbVE7kkMAABt2TLSAAAJ",
      "InternetMessageId": "<SA1PR16MB4707170FA34E36D37A414A30A2F32@SA1PR16MB4707.namprd16.prod.outlook.com>",
      "ParentFolder": {
        "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAAB",
        "Path": "\\Drafts"
      },
      "Subject": "dw-harness-afc127f4 draft (updated)"
    }
  ],
  "AppAccessContext": {
    "AADSessionId": "0022840a-e4ab-884c-587f-d20d24637227",
    "APIId": "00000003-0000-0000-c000-000000000000",
    "ClientAppId": "22222222-2222-2222-2222-222222222222",
    "IssuedAtTime": "2026-07-04T15:04:45Z",
    "UniqueTokenId": "pO6tpCIhWEeDjtm8HsIAAA"
  },
  "AppId": "00000003-0000-0000-c000-000000000000",
  "AuthType": "MSAuth1.0",
  "ClientAppId": "22222222-2222-2222-2222-222222222222",
  "ClientIP": "203.0.113.10",
  "ClientIPAddress": "203.0.113.10",
  "ClientInfoString": "Client=REST;;",
  "ClientRequestId": "c6cddfac-0a5c-4f9f-a79a-df46d90d7516",
  "CreationTime": "2026-07-04T15:09:47Z",
  "CrossMailboxOperation": false,
  "ExternalAccess": false,
  "Folder": {
    "Id": "LgAAAAAXRoXzP5fNR6PyEo/HqixAAQA7mE7t4w9CSqNKCbVE7kkMAAAAAAEPAAAB",
    "Path": "\\Drafts"
  },
  "HostAppId": "c999ed3e-27ae-4cb3-b3a2-46b056af63d3",
  "Id": "817e91e5-937b-4561-5fa3-08ded9de49aa",
  "InternalLogonType": 0,
  "LogonType": 0,
  "LogonUserSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
  "MailboxGuid": "2bc72b5a-02f0-45d2-97a2-5f0152098603",
  "MailboxOwnerSid": "S-1-5-21-2202824495-2635967380-1894632064-31996139",
  "MailboxOwnerUPN": "adminuser@example.onmicrosoft.com",
  "Operation": "SoftDelete",
  "OrganizationId": "00000000-0000-0000-0000-000000000001",
  "OrganizationName": "example.onmicrosoft.com",
  "OriginatingServer": "SA1PR16MB4707 (15.20.4200.000)\r\n",
  "RecordType": 3,
  "ResultStatus": "Succeeded",
  "SessionId": "0022840a-e4ab-884c-587f-d20d24637227",
  "TokenObjectId": "11111111-1111-1111-1111-111111111111",
  "TokenTenantId": "00000000-0000-0000-0000-000000000001",
  "TokenType": "AadPft",
  "UserId": "adminuser@example.onmicrosoft.com",
  "UserKey": "10000000AAAAAAAA",
  "UserType": 0,
  "Version": 1,
  "Workload": "Exchange"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
m365::Folder.Path (splunk rule field)in\\recoverable items\\deletions1 rulesplunk
m365::Folder.Path (splunk rule field)in\\sent items1 rulesplunk
subject (splunk rule field)in*account recovery*1 rulesplunk
subject (splunk rule field)in*banking*1 rulesplunk
subject (splunk rule field)in*direct deposit*1 rulesplunk
subject (splunk rule field)in*mfa *1 rulesplunk
subject (splunk rule field)in*otp *1 rulesplunk
subject (splunk rule field)in*passcode *1 rulesplunk
subject (splunk rule field)in*password *1 rulesplunk
subject (splunk rule field)in*pay-to*1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • M365 Exchange MFA Notification Email Deleted or Moved source low: Identifies when an MFA enrollment, registration, or security notification email is deleted or moved to deleted items in Microsoft 365 Exchange. Adversaries who compromise accounts and register their own MFA device often delete the notification emails to cover their tracks and prevent the legitimate user from noticing the unauthorized change. This technique is commonly observed in business email compromise (BEC) and account takeover attacks.T1070, T1070.008, T1098, T1098.005↳ also matches HardDelete, MoveToDeletedItems

Splunk #

References #

M365 audit records use different field names on each surface #

The same Unified Audit Log record uses different field names on each surface. A query built for one surface can silently miss on another. These pages document the Management Activity API JSON names, the same names Search-UnifiedAuditLog and the Office 365 Management Activity API return.

  • Purview CSV export flattens each record to four columns (CreationDate, UserIds, Operations, AuditData). The API field names live only inside the AuditData JSON blob. Expand it with ConvertFrom-Json. The wrapper columns are renamed too: CreationDate not CreationTime, UserIds not UserId, Operations not Operation.
  • Sentinel's OfficeActivity table renames several fields and turns two integer enum columns into strings. The table below maps them.
API JSON (event pages)OfficeActivity columnNote
IdOfficeIdRenamed.
WorkloadOfficeWorkloadRenamed.
ObjectIdOfficeObjectIdRenamed.
CreationTimeTimeGeneratedRenamed. OfficeActivity has no CreationTime column.
SiteUrlSite_UrlRenamed (SharePoint family).
RecordTypeRecordTypeSame name; the Int32 enum becomes its string enum name.
UserTypeUserTypeSame name; the Int32 enum becomes a string.
ClientIPClientIP, Client_IPAddressBoth columns present on OfficeActivity.
Scope(none)No OfficeActivity equivalent under any name. Recover it from the API JSON or the Purview AuditData blob.
Operation, UserId, ResultStatus, UserKey, AppAccessContext, OrganizationIdsame namesUnchanged. No _s / _d suffixes (a native table, not a custom log).

Mapping verified against the OfficeActivity table reference, the Management Activity API schema, and the Purview audit-record export format.