Cross-source coverage

T1114 / ATT&CK

Email Collection

104 rules · 103 families across 9 sources.

3 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.

Tactics
Collection
Platforms
Windows · macOS · Linux · Office Suite
Telemetry
WinEventLog:SecurityWinEventLog:PowerShellWinEventLog:ApplicationWinEventLog:Sysmonauditd:SYSCALLlinux:sysloglinux:osquerymacos:unifiedlogmacos:endpointsecuritym365:unifiedm365:exchangeazure:ad

How MITRE says to detect it DET0476

Email Collection via Local Email Access and Auto-Forwarding Behavior

Windows Analytic 1309

Correlates creation of email forwarding rules or header anomalies (e.g., X-MS-Exchange-Organization-AutoForwarded) with suspicious process execution, file access of.pst/.ost files, and network connections to external SMTP servers.

  • WinEventLog:Security EventCode=5145
  • WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106
  • WinEventLog:Application Exchange logs or header artifacts
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 1310

Detects file access to mbox/maildir files in conjunction with curl/wget/postfix execution, or anomalous shell scripts harvesting user mail directories.

  • auditd:SYSCALL open
  • linux:syslog postfix/smtpd
  • linux:osquery process_events

macOS Analytic 1311

Monitors Mail.app database or maildir file access, automation via AppleScript, and abnormal mail rule creation using scripting or UI automation frameworks.

  • macos:unifiedlog Mail or AppleScript subsystem
  • macos:endpointsecurity es_event_open, es_event_exec

Office Suite Analytic 1312

Correlates unusual auto-forwarding rule creation via Exchange Web Services or Outlook rules engine, presence of X-MS-Exchange-Organization-AutoForwarded headers, and logon session anomalies from abnormal IPs.

  • m365:unified Set-Mailbox, New-InboxRule
  • m365:exchange MessageTrace logs
  • azure:ad SignInEvents

Sub-techniques with coverage

Counted in the 104 above — a rule tagged a sub-technique covers this technique too.


Wazuh Core Ruleset

39 rules · 38 families
Detection Severity Format
(bad sequence of commands). High Wazuh XML
from invalid/unknown sender domain. High Wazuh XML
invalid recipient or from unknown sender domain. High Wazuh XML
invalid/unknown sender. High Wazuh XML
invalid/unknown sender domain. High Wazuh XML
It should not be sending e-mail. High Wazuh XML
Outlook add-in was loaded by powershell, possible use for email collection High Wazuh XML
Powershell initializing MS Exchange snapin. Possible mailbox data dump High Wazuh XML
sendmail: Multiple pre-greetings rejects. High Wazuh XML
sendmail: Multiple rejected e-mails from same source ip. High Wazuh XML

+ 29 more from Wazuh Core Ruleset → showing the 10 highest-severity

splunk/security_content

25 rules
Detection Severity Format
Email files written outside of the Outlook directory Undefined SPL
Email servers sending high volume traffic to hosts Undefined SPL
Hosts receiving high volume of network traffic from email server Undefined SPL
Mailsniper Invoke functions Undefined SPL
O365 Compliance Content Search Exported Undefined SPL
O365 Compliance Content Search Started Undefined SPL
O365 Email Access By Security Administrator Undefined SPL
O365 Email New Inbox Rule Created Undefined SPL
O365 Email Password and Payroll Compromise Behavior Undefined SPL
O365 Email Receive and Hard Delete Takeover Behavior Undefined SPL

+ 15 more from splunk/security_content → showing the 10 highest-severity

SigmaHQ/sigma

11 rules
Detection Severity Format
Exchange PowerShell Snap-Ins Usage High Sigma
Hacktool Ruler High Sigma
Suspicious Inbox Forwarding Identity Protection High Sigma
Google Workspace Out Of Domain Email Forwarding Medium Sigma
Inbox Rules Creation Or Update Activity in O365 Medium Sigma
Inbox Rules Creation Or Update Activity Via ExchangePowerShell Cmdlet Medium Sigma
Mail Forwarding/Redirecting Activity In O365 Medium Sigma
Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet Medium Sigma
Powershell Local Email Collection Medium Sigma
PST Export Alert Using eDiscovery Alert Medium Sigma

+ 1 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

11 rules
Detection Severity Format
Google Workspace Gmail Routing or Forwarding Rule Created or Modified High Elastic TOML
Exchange Mailbox Export via PowerShell Medium Elastic TOML
Exporting Exchange Mailbox via PowerShell Medium Elastic TOML
M365 Exchange Inbox Forwarding Rule Created Medium Elastic TOML
M365 Exchange Mailbox Accessed by Unusual Client Medium Elastic TOML
M365 Exchange Mailbox Items Accessed Excessively Medium Elastic TOML
M365 Exchange Mail Flow Transport Rule Created Medium Elastic TOML
Microsoft Graph Email Access by Unusual User and Client Medium Elastic TOML
New ActiveSyncAllowedDeviceID Added via PowerShell Medium Elastic TOML
PowerShell Mailbox Collection Script Medium Elastic TOML

+ 1 more from elastic/detection-rules → showing the 10 highest-severity

socfortress/Wazuh-Rules

7 rules
Detection Severity Format
operation. · office_365.Operation = UserSubmission High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell Email Collection Get-Inbox.ps1 (T1114.001) High Wazuh XML
operation. · office_365.Operation = CreateResponse Low Wazuh XML
operation. · office_365.Operation = MessageCreation Low Wazuh XML
operation. · office_365.Operation = MessageEditedHasLink Low Wazuh XML
operation. · office_365.Operation = MessageUpdated Low Wazuh XML
operation. · office_365.Operation = QuarantineViewMessageHeader Low Wazuh XML

Azure/Azure-Sentinel

5 rules
Detection Severity Format
High risk Office operation conducted by IP Address that recently attempted to log into a disabled account Medium KQL
NRT Multiple users email forwarded to same destination Medium KQL
Host Exporting Mailbox and Removing Export (Normalized Process Events) Undefined KQL
New Location Sign in with Mail forwarding activity Undefined KQL
Rare domains seen in Cloud Logs Undefined KQL

panther-labs/panther-analysis

3 rules
Detection Severity Format
Microsoft Exchange External Forwarding High Panther Python
AppOmni Alert Passthrough Medium Panther Python
Gsuite Mail forwarded to external domain Medium Panther Python

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
Big Yellow Taxi - SignIn Based Undefined KQL
MITRE ATT&CK Mapping Undefined KQL

Emerging Threats Open

1 rule
Detection Severity Format
ET MALWARE JS ZimReaper Zimbra Mailbox Archive Export High Suricata

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.