Cross-source coverage
T1114 / ATT&CK
Email Collection
107 rules · 106 families across 10 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.
- Tactics
- Collection
- Platforms
- Windows · macOS · Linux · Office Suite
- Telemetry
-
WinEventLog:SecurityWinEventLog:PowerShellWinEventLog:ApplicationWinEventLog:Sysmonauditd:SYSCALLlinux:sysloglinux:osquerymacos:unifiedlogmacos:endpointsecuritym365:unifiedm365:exchangeazure:ad
How MITRE says to detect it DET0476
Email Collection via Local Email Access and Auto-Forwarding Behavior
Windows Analytic 1309
Correlates creation of email forwarding rules or header anomalies (e.g., X-MS-Exchange-Organization-AutoForwarded) with suspicious process execution, file access of.pst/.ost files, and network connections to external SMTP servers.
WinEventLog:SecurityEventCode=5145WinEventLog:PowerShellEventCode=4103, 4104, 4105, 4106WinEventLog:ApplicationExchange logs or header artifactsWinEventLog:SysmonEventCode=3, 22
Linux Analytic 1310
Detects file access to mbox/maildir files in conjunction with curl/wget/postfix execution, or anomalous shell scripts harvesting user mail directories.
auditd:SYSCALLopenlinux:syslogpostfix/smtpdlinux:osqueryprocess_events
macOS Analytic 1311
Monitors Mail.app database or maildir file access, automation via AppleScript, and abnormal mail rule creation using scripting or UI automation frameworks.
macos:unifiedlogMail or AppleScript subsystemmacos:endpointsecurityes_event_open, es_event_exec
Office Suite Analytic 1312
Correlates unusual auto-forwarding rule creation via Exchange Web Services or Outlook rules engine, presence of X-MS-Exchange-Organization-AutoForwarded headers, and logon session anomalies from abnormal IPs.
m365:unifiedSet-Mailbox, New-InboxRulem365:exchangeMessageTrace logsazure:adSignInEvents
Sub-techniques with coverage
Counted in the 107 above — a rule tagged a sub-technique covers this technique too.
Wazuh Core Ruleset
39 rules · 38 families| Detection | Severity | Format |
|---|---|---|
| (bad sequence of commands). | High | Wazuh XML |
| from invalid/unknown sender domain. | High | Wazuh XML |
| invalid recipient or from unknown sender domain. | High | Wazuh XML |
| invalid/unknown sender. | High | Wazuh XML |
| invalid/unknown sender domain. | High | Wazuh XML |
| It should not be sending e-mail. | High | Wazuh XML |
| Outlook add-in was loaded by powershell, possible use for email collection | High | Wazuh XML |
| Powershell initializing MS Exchange snapin. Possible mailbox data dump | High | Wazuh XML |
| sendmail: Multiple pre-greetings rejects. | High | Wazuh XML |
| sendmail: Multiple rejected e-mails from same source ip. | High | Wazuh XML |
+ 29 more from Wazuh Core Ruleset → showing the 10 highest-severity
splunk/security_content
25 rules| Detection | Severity | Format |
|---|---|---|
| Email files written outside of the Outlook directory | Undefined | SPL |
| Email servers sending high volume traffic to hosts | Undefined | SPL |
| Hosts receiving high volume of network traffic from email server | Undefined | SPL |
| Mailsniper Invoke functions | Undefined | SPL |
| O365 Compliance Content Search Exported | Undefined | SPL |
| O365 Compliance Content Search Started | Undefined | SPL |
| O365 Email Access By Security Administrator | Undefined | SPL |
| O365 Email New Inbox Rule Created | Undefined | SPL |
| O365 Email Password and Payroll Compromise Behavior | Undefined | SPL |
| O365 Email Receive and Hard Delete Takeover Behavior | Undefined | SPL |
+ 15 more from splunk/security_content → showing the 10 highest-severity
SigmaHQ/sigma
11 rules| Detection | Severity | Format |
|---|---|---|
| Exchange PowerShell Snap-Ins Usage | High | Sigma |
| Hacktool Ruler | High | Sigma |
| Suspicious Inbox Forwarding Identity Protection | High | Sigma |
| Google Workspace Out Of Domain Email Forwarding | Medium | Sigma |
| Inbox Rules Creation Or Update Activity in O365 | Medium | Sigma |
| Inbox Rules Creation Or Update Activity Via ExchangePowerShell Cmdlet | Medium | Sigma |
| Mail Forwarding/Redirecting Activity In O365 | Medium | Sigma |
| Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet | Medium | Sigma |
| Powershell Local Email Collection | Medium | Sigma |
| PST Export Alert Using eDiscovery Alert | Medium | Sigma |
+ 1 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
11 rules| Detection | Severity | Format |
|---|---|---|
| Google Workspace Gmail Routing or Forwarding Rule Created or Modified | High | Elastic TOML |
| Exchange Mailbox Export via PowerShell | Medium | Elastic TOML |
| Exporting Exchange Mailbox via PowerShell | Medium | Elastic TOML |
| M365 Exchange Inbox Forwarding Rule Created | Medium | Elastic TOML |
| M365 Exchange Mailbox Accessed by Unusual Client | Medium | Elastic TOML |
| M365 Exchange Mailbox Items Accessed Excessively | Medium | Elastic TOML |
| M365 Exchange Mail Flow Transport Rule Created | Medium | Elastic TOML |
| Microsoft Graph Email Access by Unusual User and Client | Medium | Elastic TOML |
| New ActiveSyncAllowedDeviceID Added via PowerShell | Medium | Elastic TOML |
| PowerShell Mailbox Collection Script | Medium | Elastic TOML |
+ 1 more from elastic/detection-rules → showing the 10 highest-severity
socfortress/Wazuh-Rules
7 rules| Detection | Severity | Format |
|---|---|---|
| operation. · office_365.Operation = UserSubmission | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell Email Collection Get-Inbox.ps1 (T1114.001) | High | Wazuh XML |
| operation. · office_365.Operation = CreateResponse | Low | Wazuh XML |
| operation. · office_365.Operation = MessageCreation | Low | Wazuh XML |
| operation. · office_365.Operation = MessageEditedHasLink | Low | Wazuh XML |
| operation. · office_365.Operation = MessageUpdated | Low | Wazuh XML |
| operation. · office_365.Operation = QuarantineViewMessageHeader | Low | Wazuh XML |
Azure/Azure-Sentinel
5 rules| Detection | Severity | Format |
|---|---|---|
| High risk Office operation conducted by IP Address that recently attempted to log into a disabled account | Medium | KQL |
| NRT Multiple users email forwarded to same destination | Medium | KQL |
| Host Exporting Mailbox and Removing Export (Normalized Process Events) | Undefined | KQL |
| New Location Sign in with Mail forwarding activity | Undefined | KQL |
| Rare domains seen in Cloud Logs | Undefined | KQL |
chronicle/detection-rules
3 rules| Detection | Severity | Format |
|---|---|---|
| a_variant_of_data_stealer_trojan_activity | Undefined | YARA-L |
| hacktool_use | Undefined | YARA-L |
| mydoom_email_worm_detector_sysmon_behavior | Undefined | YARA-L |
panther-labs/panther-analysis
3 rules| Detection | Severity | Format |
|---|---|---|
| Microsoft Exchange External Forwarding | High | Panther Python |
| AppOmni Alert Passthrough | Medium | Panther Python |
| Gsuite Mail forwarded to external domain | Medium | Panther Python |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Big Yellow Taxi - SignIn Based | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
Emerging Threats Open
1 rule| Detection | Severity | Format |
|---|---|---|
| ET MALWARE JS ZimReaper Zimbra Mailbox Archive Export | High | Suricata |