Sub-technique of T1070 Indicator Removal.View on attack.mitre.org
Adversaries may modify mail and mail application data to remove evidence of their activity. Email applications allow users and other programs to export and delete mailbox data via command line tools or use of APIs. Mail application data can be emails, email metadata, or logs generated by the application or operating system, such as export requests.
Adversaries may manipulate emails and mailbox data to remove logs, artifacts, and metadata, such as evidence of Phishing/Internal Spearphishing, Email Collection, Mail Protocols for command and control, or email-based exfiltration such as Exfiltration Over Alternative Protocol. For example, to remove evidence on Exchange servers adversaries have used the ExchangePowerShell PowerShell module, including Remove-MailboxExportRequest to remove evidence of mailbox exports. On Linux and macOS, adversaries may also delete emails through a command line utility called mail or use AppleScript to interact with APIs on macOS.
Adversaries may also remove emails and metadata/headers indicative of spam or suspicious activity (for example, through the use of organization-wide transport rules) to reduce the likelihood of malicious emails being detected by security products.
Rules on DetectionCode tagged with T1070.008.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco ASA - User Account Deleted From Local Database | Anomaly | NULL | Cisco ASA Logs |
| O365 Email Hard Delete Excessive Volume | Anomaly | NULL | Office 365 Universal Audit Log |
| O365 Email Password and Payroll Compromise Behavior | TTP | NULL | Office 365 Universal Audit Log, Office 365 Reporting Message Trace |
| O365 Email Receive and Hard Delete Takeover Behavior | Anomaly | NULL | Office 365 Universal Audit Log, Office 365 Reporting Message Trace |
| O365 Email Send and Hard Delete Exfiltration Behavior | Anomaly | NULL | Office 365 Universal Audit Log, Office 365 Reporting Message Trace |
| O365 Email Send and Hard Delete Suspicious Behavior | Anomaly | NULL | Office 365 Universal Audit Log |
| O365 Email Send Attachments Excessive Volume | Anomaly | NULL | Office 365 Universal Audit Log |
| Used by | Procedure example |
|---|---|
| GroupAPT42 | APT42 has deleted login notification emails and has cleared the Sent folder to cover their tracks. |
| GroupScattered Spider | Scattered Spider has manually deleted emails notifying users of suspicious account activity. |
| Used by | Procedure example |
|---|---|
| MalwareGoopy | Goopy has the ability to delete emails used for C2 once the content has been copied. |
| MalwareLunarMail | LunarMail can set the `PR_DELETE_AFTER_SUBMIT` flag to delete messages sent for data exfiltration. |
| Used by | Procedure example |
|---|---|
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 removed evidence of email export requests using `Remove-MailboxExportRequest`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.