Techniques › T1684.002 › AN1204
AN1204 Analytic 1204
macOS · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects suspicious inbound mail traffic where SPF/DKIM/DMARC authentication fails or where sender and return-path domains mismatch, observable in Apple Mail unified logs or MDM-controlled logging pipelines.</p>
- Detects
- T1684.002 Email Spoofing
- Part of
- DET0431 Detection Strategy for Email Spoofing
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| macos:unifiedlog | SPF fail OR DKIM fail OR DMARC fail OR mismatched header vs envelope domains | DC0038 Application Log Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
RecipientSensitivity | Allows tuning based on which users (e.g., executives, finance staff) receive stricter spoofing detection policies. |
HeaderMismatchTolerance | Defines tolerance for minor discrepancies in domain alignment, balancing detection with usability. |