Cross-source coverage

T1114.002 / ATT&CK

Email Collection: Remote Email Collection

18 rules across 2 sources.

From MITRE ATT&CK 19.2

Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.

Tactics
Collection
Platforms
Office Suite · Windows
Telemetry
azure:signinlogsm365:purviewWinEventLog:PowerShellWinEventLog:Sysmonm365:unified

How MITRE says to detect it DET0048

Detect Remote Email Collection via Abnormal Login and Programmatic Access

Windows Analytic 0131

Detects adversaries accessing remote mail systems (e.g., Exchange Online, O365) using stolen credentials or OAuth tokens, followed by scripted access to mailbox contents via PowerShell, AADInternals, or unattended API queries. Detection focuses on abnormal logon sessions, user agents, IP locations, and scripted or tool-based email data access.

  • azure:signinlogs Abnormal sign-in from scripting tools (PowerShell, AADInternals)
  • m365:purview MailItemsAccessed & Exchange Audit
  • WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106
  • WinEventLog:Sysmon EventCode=3, 22

Office Suite Analytic 0132

Monitors programmatic access to user mailboxes in cloud-based email systems (e.g., O365, Exchange Online) using APIs or tokens. Focuses on OAuth misuse, suspicious MailItemsAccessed patterns, scripted keyword searches, and connections from untrusted agents or locations.

  • m365:purview MailItemsAccessed, Search-Mailbox events
  • azure:signinlogs Suspicious login to cloud mailbox system
  • m365:unified Search-Mailbox, Get-MessageTrace, eDiscovery requests

splunk/security_content

11 rules
Detection Severity Format
Email servers sending high volume traffic to hosts Undefined SPL
Hosts receiving high volume of network traffic from email server Undefined SPL
O365 Compliance Content Search Exported Undefined SPL
O365 Compliance Content Search Started Undefined SPL
O365 Email Access By Security Administrator Undefined SPL
O365 Email Suspicious Search Behavior Undefined SPL
O365 Mailbox Inbox Folder Shared with All Users Undefined SPL
O365 Mailbox Read Access Granted to Application Undefined SPL
O365 Multiple Mailboxes Accessed via API Undefined SPL
O365 OAuth App Mailbox Access via EWS Undefined SPL

+ 1 more from splunk/security_content → showing the 10 highest-severity

elastic/detection-rules

7 rules
Detection Severity Format
Exchange Mailbox Export via PowerShell Medium Elastic TOML
Exporting Exchange Mailbox via PowerShell Medium Elastic TOML
M365 Exchange Mailbox Accessed by Unusual Client Medium Elastic TOML
M365 Exchange Mailbox Items Accessed Excessively Medium Elastic TOML
Microsoft Graph Email Access by Unusual User and Client Medium Elastic TOML
New ActiveSyncAllowedDeviceID Added via PowerShell Medium Elastic TOML
PowerShell Mailbox Collection Script Medium Elastic TOML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.