{"id":3885,"date":"2019-02-03T06:45:30","date_gmt":"2019-02-03T06:45:30","guid":{"rendered":"https:\/\/pariswells.com\/blog\/?p=3885"},"modified":"2019-02-03T06:50:39","modified_gmt":"2019-02-03T06:50:39","slug":"find-out-when-outlook-rule-was-created","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/research\/find-out-when-outlook-rule-was-created","title":{"rendered":"Find out when outlook rule was created"},"content":{"rendered":"\n<p>With the increase attack on 365 subscriptions without two factor enabled its good to check when a rule actually got added. This cannot be done with powershell you will need to perform with MFCMAPI<\/p>\n\n\n\n<p>Download the latest MFCMAPI of 32bit or 64bit ( depending on your Office\/Outlook version ) release  <a href=\"https:\/\/github.com\/stephenegriffin\/mfcmapi\/releases\/latest\">here<\/a><\/p>\n\n\n\n<p>You can do this on the User&#8217;s computer who should already have Outlook installed or you can create an Outlook profile as the user you would like to check the rule for on another PC. You can also create an Outlook Profile as an Administrator and give yourself full access to the User&#8217;s <g class=\"gr_ gr_4 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace\" id=\"4\" data-gr-id=\"4\">Maibox<\/g><\/p>\n\n\n\n<p>Open  MFCMAPI  , Open the Profile , then go to Session and Logon<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"183\" height=\"80\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image.png\" alt=\"\" class=\"wp-image-3886 img-responsive\"\/><\/figure>\n\n\n\n<p>Double click on the account<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"487\" height=\"84\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-1.png\" alt=\"\" class=\"wp-image-3887 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-1.png 487w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-1-300x52.png 300w\" sizes=\"auto, (max-width: 487px) 100vw, 487px\" \/><\/figure>\n\n\n\n<p>Open the Root Folder and Navigate to here and right click on Inbox and Choose Open Associated Contents Table<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"366\" height=\"323\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-2.png\" alt=\"\" class=\"wp-image-3888 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-2.png 366w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-2-300x265.png 300w\" sizes=\"auto, (max-width: 366px) 100vw, 366px\" \/><\/figure>\n\n\n\n<p>The rule will look something like this , Message Class : IPM.Rule.Verson2.Message<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1464\" height=\"51\" src=\"https:\/\/i2.wp.com\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-3.png?fit=1024%2C36&amp;ssl=1\" alt=\"\" class=\"wp-image-3889 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-3.png 1464w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-3-300x10.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-3-768x27.png 768w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-3-1024x36.png 1024w\" sizes=\"auto, (max-width: 1464px) 100vw, 1464px\" \/><figcaption>Double click on this<\/figcaption><\/figure>\n\n\n\n<p>Then find the following Name and check the value to confirm its the right Rule<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"762\" height=\"61\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-6.png\" alt=\"\" class=\"wp-image-3892 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-6.png 762w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-6-300x24.png 300w\" sizes=\"auto, (max-width: 762px) 100vw, 762px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"921\" height=\"82\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-5.png\" alt=\"\" class=\"wp-image-3891 img-responsive\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-5.png 921w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-5-300x27.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2019\/02\/image-5-768x68.png 768w\" sizes=\"auto, (max-width: 921px) 100vw, 921px\" \/><figcaption>Then Use this Rule to find the Date Created<\/figcaption><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>With the increase attack on 365 subscriptions without two factor enabled its good to check when a rule actually got added. This cannot be done with powershell [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2811,2810,2809,560,1687],"class_list":["post-3885","post","type-post","status-publish","format-standard","hentry","category-research","tag-created","tag-inbox-rule","tag-mfcmapi","tag-outlook","tag-time"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/3885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=3885"}],"version-history":[{"count":1,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/3885\/revisions"}],"predecessor-version":[{"id":3893,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/3885\/revisions\/3893"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=3885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=3885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=3885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}