Email Collection

T1114

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.

Detection rules35

Rules on DetectionCode tagged with T1114 or one of its sub-techniques.

Sigma7

Splunk28

RuleTypeRiskData sourceTechnique
Email files written outside of the Outlook directoryAnomalyNULLSysmon EventID 11T1114.001
Email servers sending high volume traffic to hostsAnomalyNULLT1114.002
Hosts receiving high volume of network traffic from email serverAnomalyNULLT1114.002
Mailsniper Invoke functionsTTPNULLPowershell Script Block Logging 4104T1114.001
O365 Compliance Content Search ExportedTTPNULLT1114.002
O365 Compliance Content Search StartedTTPNULLT1114.002
O365 Email Access By Security AdministratorTTPNULLOffice 365 Universal Audit LogT1114.002
O365 Email New Inbox Rule CreatedAnomalyNULLOffice 365 Universal Audit LogT1114.003
O365 Email Password and Payroll Compromise BehaviorTTPNULLOffice 365 Universal Audit Log, Office 365 Reporting Message TraceT1114.001
O365 Email Receive and Hard Delete Takeover BehaviorAnomalyNULLOffice 365 Universal Audit Log, Office 365 Reporting Message TraceT1114.001
O365 Email Send and Hard Delete Exfiltration BehaviorAnomalyNULLOffice 365 Universal Audit Log, Office 365 Reporting Message TraceT1114.001
O365 Email Send and Hard Delete Suspicious BehaviorAnomalyNULLOffice 365 Universal Audit LogT1114.001
O365 Email Suspicious Behavior AlertTTPNULLOffice 365 Universal Audit LogT1114.003
O365 Email Suspicious Search BehaviorAnomalyNULLOffice 365 Universal Audit LogT1114.002
O365 Email Transport Rule ChangedAnomalyNULLOffice 365 Universal Audit LogT1114.003

Sub-techniques3

IDNameExamples
T1114.001Local Email Collection20
T1114.002Remote Email Collection20
T1114.003Email Forwarding Rule5

Groups4

Software2

Campaigns0

None recorded.

Procedure examples6

Groups4

Used byProcedure example
GroupEmber Bear

Ember Bear attempts to collect mail from accessed systems and servers.

GroupMagic Hound

Magic Hound has compromised email credentials in order to steal sensitive data.

GroupScattered Spider

Scattered Spider searched the victim’s Microsoft Exchange for emails about the intrusion and incident response.

GroupSilent Librarian

Silent Librarian has exfiltrated entire mailboxes from compromised accounts.

Software2

Used byProcedure example
MalwareEmotet

Emotet has been observed leveraging a module that can scrape email addresses from Outlook.

MalwareTRANSLATEXT

TRANSLATEXT has exfiltrated collected email addresses to the C2 server.

References2

  1. CISA AA20-352A 2021 Open source
    CISA. (2021, April 15). Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations. Retrieved August 30, 2024.
  2. TrustedSec OOB Communications Open source
    Tyler Hudak. (2022, December 29). To OOB, or Not to OOB?: Why Out-of-Band Communications are Essential for Incident Response. Retrieved August 30, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.