Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Discovery

T1087.003 Email Account

Sub-technique of T1087 Account Discovery

Adversaries may attempt to get a listing of email addresses and accounts. Adversaries may try to dump Exchange address lists such as global address lists (GALs).(Citation: Microsoft Exchange Address Lists) In on-premises Exchange and Exchange Online, the Get-GlobalAddressList PowerShell cmdlet can be used to obtain email addresses and accounts from a domain using an authenticated…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

SigmaHQ has no rules for this technique.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.