ITM is an open framework - Submit your contributions now.

Insider Threat Matrix™

  • ID: AF027.002
  • Created: 11th August 2025
  • Updated: 17th August 2025
  • Contributor: The ITM Team

Auto-Forwarding Rule Deletion

The subject removes one or more auto-forwarding rules from their email configuration to obscure prior message redirection to internal or external recipients. These rules, when active, silently transmit inbound emails, including attachments, proprietary data, or sensitive internal correspondence, to alternate mailboxes, often controlled or accessible by the subject. Deletion is typically performed to disrupt investigative reconstruction, eliminate configuration evidence, and frustrate detection of unauthorized forwarding behavior.