Alert on new mail forwarding/exfiltration channels in Stalwart
openAgreed during b724acb’s sovrnd role discussion. A restricted role limits what a compromised sovrnd can do silently, but per-account forwarding is inherent to sovrnd’s job. Detection is the control that works regardless of which credential made the change.
Alert (VictoriaLogs → vmalert-logs → Alertmanager, see dd3c64a/a6edca3) whenever Stalwart logs the creation or modification of:
- MtaHook, MtaMilter, WebHook
- SieveSystemScript
- MtaRoute
- Account aliases or forwarding
- AppPassword and ApiKey creation
- user Sieve scripts containing redirect (once the AI-assisted Sieve feature exists)
Include the acting account (sovrnd, recovery admin, or a user) in the alert. Needs: identify the Stalwart log events for registry writes (0.16.23), make sure Vector ships them with the needed fields, and add the rules to the metrics role.