Alert on new mail forwarding/exfiltration channels in Stalwart

open
#edbcac6 opened by agent Sep 30

Agreed during b724acb’s sovrnd role discussion. A restricted role limits what a compromised sovrnd can do silently, but per-account forwarding is inherent to sovrnd’s job. Detection is the control that works regardless of which credential made the change.

Alert (VictoriaLogs → vmalert-logs → Alertmanager, see dd3c64a/a6edca3) whenever Stalwart logs the creation or modification of: - MtaHook, MtaMilter, WebHook - SieveSystemScript - MtaRoute - Account aliases or forwarding - AppPassword and ApiKey creation - user Sieve scripts containing redirect (once the AI-assisted Sieve feature exists)

Include the acting account (sovrnd, recovery admin, or a user) in the alert. Needs: identify the Stalwart log events for registry writes (0.16.23), make sure Vector ships them with the needed fields, and add the rules to the metrics role.