Microsoft's own guidance on compromised mailboxes lists suspicious inbox rules as a warning sign: rules that auto-forward mail to unknown addresses, and rules that quietly move messages into Notes, Junk Email, or RSS Subscriptions. MITRE ATT&CK tracks email forwarding rules as a specific sub-technique (T1114.003).
Why RSS Subscriptions? Because nobody looks there.
In a BEC play, that's how the attacker keeps the real person in the dark. The vendor's actual reply gets buried, the fake conversation keeps going, and the money moves.
When I'm working a possible account compromise, inbox rules are one of the first things I pull. A rule the user swears they didn't create tells you more than half the alerts in the queue.