T1114 Email Collection
Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses.(Citation: TrustedSec OOB…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Exchange PowerShell Snap-Ins Usagehightest · windows
- Hacktool Rulerhightest · windows
- Suspicious Inbox Forwarding Identity Protectionhightest · azure
- PST Export Alert Using New-ComplianceSearchActionmediumtest · m365
- PST Export Alert Using eDiscovery Alertmediumtest · m365
- Powershell Local Email Collectionmediumtest · windows
- Google Workspace Out Of Domain Email Forwardingmediumexperimental · gcp
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.