kevmap

TechniquesT1684.002 › AN1204

AN1204 Analytic 1204

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects suspicious inbound mail traffic where SPF/DKIM/DMARC authentication fails or where sender and return-path domains mismatch, observable in Apple Mail unified logs or MDM-controlled logging pipelines.</p>
Detects
T1684.002 Email Spoofing
Part of
DET0431 Detection Strategy for Email Spoofing

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogSPF fail OR DKIM fail OR DMARC fail OR mismatched header vs envelope domainsDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
RecipientSensitivityAllows tuning based on which users (e.g., executives, finance staff) receive stricter spoofing detection policies.
HeaderMismatchToleranceDefines tolerance for minor discrepancies in domain alignment, balancing detection with usability.