kevmap

TechniquesT1087.003 › AN0642

AN0642 Analytic 0642

Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Suspicious querying of organization-wide directory data via Google Workspace Directory API or Outlook GAL sync in high volume from abnormal users, service accounts, or unknown device contexts.</p>
Detects
T1087.003 Email Account
Part of
DET0229 Enumeration of Global Address Lists via Email Account Discovery

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
gcp:auditDirectory API Access: users.list or groups.listDC0013 User Account Metadata
m365:unifiedGAL Lookup or Address Book downloadDC0038 Application Log Content
azure:signinlogsUnusual Token Usage or Application ConsentDC0002 User Account Authentication

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
APIQueryVolumeSet thresholds for excessive use of 'users.list' or recursive group enumerations.
UserContextFlag non-admin or previously unseen user agents requesting directory information.
AppSourceDistinguish between sanctioned sync tools and unauthorized scripts or OAuth tokens.