kevmap

TechniquesT1684.001 › AN0793

AN0793 Analytic 0793

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Monitor mail server logs (Postfix, Sendmail, Exim) for anomalous From headers mismatching authenticated SMTP identities. Detect abnormal relay attempts, spoofed envelope-from values, or large-scale outbound campaigns targeting internal users.</p>
Detects
T1684.001 Impersonation
Part of
DET0286 Detection Strategy for Impersonation

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLexecve: Processes executing sendmail/postfix with forged headersDC0064 Command Execution
Application:MailMismatch between authenticated username and From header in emailDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
KnownRelayHostsFilter trusted relays or automated notification systems from impersonation alerts.