Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.
Rules on DetectionCode tagged with T1114 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| Exchange PowerShell Snap-Ins Usage | high | windows / process_creation | T1114 |
| Hacktool Ruler | high | windows / NULL | T1114 |
| Suspicious Inbox Forwarding Identity Protection | high | azure / NULL | T1114.003 |
| Google Workspace Out Of Domain Email Forwarding | medium | gcp / NULL | T1114.003 |
| Powershell Local Email Collection | medium | windows / ps_script | T1114.001 |
| PST Export Alert Using eDiscovery Alert | medium | m365 / NULL | T1114 |
| PST Export Alert Using New-ComplianceSearchAction | medium | m365 / NULL | T1114 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupEmber Bear | Ember Bear attempts to collect mail from accessed systems and servers. |
| GroupMagic Hound | Magic Hound has compromised email credentials in order to steal sensitive data. |
| GroupScattered Spider | Scattered Spider searched the victim’s Microsoft Exchange for emails about the intrusion and incident response. |
| GroupSilent Librarian | Silent Librarian has exfiltrated entire mailboxes from compromised accounts. |
| Used by | Procedure example |
|---|---|
| MalwareEmotet | Emotet has been observed leveraging a module that can scrape email addresses from Outlook. |
| MalwareTRANSLATEXT | TRANSLATEXT has exfiltrated collected email addresses to the C2 server. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.