Cross-source coverage
T1114.002 / ATT&CK
Email Collection: Remote Email Collection
18 rules across 2 sources.
From MITRE ATT&CK 19.2
Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.
- Tactics
- Collection
- Platforms
- Office Suite · Windows
- Telemetry
-
azure:signinlogsm365:purviewWinEventLog:PowerShellWinEventLog:Sysmonm365:unified
How MITRE says to detect it DET0048
Detect Remote Email Collection via Abnormal Login and Programmatic Access
Windows Analytic 0131
Detects adversaries accessing remote mail systems (e.g., Exchange Online, O365) using stolen credentials or OAuth tokens, followed by scripted access to mailbox contents via PowerShell, AADInternals, or unattended API queries. Detection focuses on abnormal logon sessions, user agents, IP locations, and scripted or tool-based email data access.
azure:signinlogsAbnormal sign-in from scripting tools (PowerShell, AADInternals)m365:purviewMailItemsAccessed & Exchange AuditWinEventLog:PowerShellEventCode=4103, 4104, 4105, 4106WinEventLog:SysmonEventCode=3, 22
Office Suite Analytic 0132
Monitors programmatic access to user mailboxes in cloud-based email systems (e.g., O365, Exchange Online) using APIs or tokens. Focuses on OAuth misuse, suspicious MailItemsAccessed patterns, scripted keyword searches, and connections from untrusted agents or locations.
m365:purviewMailItemsAccessed, Search-Mailbox eventsazure:signinlogsSuspicious login to cloud mailbox systemm365:unifiedSearch-Mailbox, Get-MessageTrace, eDiscovery requests
splunk/security_content
11 rules| Detection | Severity | Format |
|---|---|---|
| Email servers sending high volume traffic to hosts | Undefined | SPL |
| Hosts receiving high volume of network traffic from email server | Undefined | SPL |
| O365 Compliance Content Search Exported | Undefined | SPL |
| O365 Compliance Content Search Started | Undefined | SPL |
| O365 Email Access By Security Administrator | Undefined | SPL |
| O365 Email Suspicious Search Behavior | Undefined | SPL |
| O365 Mailbox Inbox Folder Shared with All Users | Undefined | SPL |
| O365 Mailbox Read Access Granted to Application | Undefined | SPL |
| O365 Multiple Mailboxes Accessed via API | Undefined | SPL |
| O365 OAuth App Mailbox Access via EWS | Undefined | SPL |
+ 1 more from splunk/security_content → showing the 10 highest-severity
elastic/detection-rules
7 rules| Detection | Severity | Format |
|---|---|---|
| Exchange Mailbox Export via PowerShell | Medium | Elastic TOML |
| Exporting Exchange Mailbox via PowerShell | Medium | Elastic TOML |
| M365 Exchange Mailbox Accessed by Unusual Client | Medium | Elastic TOML |
| M365 Exchange Mailbox Items Accessed Excessively | Medium | Elastic TOML |
| Microsoft Graph Email Access by Unusual User and Client | Medium | Elastic TOML |
| New ActiveSyncAllowedDeviceID Added via PowerShell | Medium | Elastic TOML |
| PowerShell Mailbox Collection Script | Medium | Elastic TOML |