{"id":"T1071.003","name":"Mail Protocols","url":"https://attack.mitre.org/techniques/T1071/003","tactics":["command-and-control"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0135","stix_id":"x-mitre-detection-strategy--bcb3772f-25d7-4e41-8e37-ec0dc759f44d","name":"Detection of Mail Protocol-Based C2 Activity (SMTP, IMAP, POP3)","url":"https://attack.mitre.org/detectionstrategies/DET0135","analytics":[{"id":"AN0379","stix_id":"x-mitre-analytic--aef3d563-19f5-4d52-b7ad-4c4abadcb568","name":"Analytic 0379","description":"Detects unauthorized use of SMTP/IMAP/POP3 by suspicious binaries (e.g., PowerShell, rundll32) to exfiltrate data or beacon via email, often bypassing proxy or content filters.","url":"https://attack.mitre.org/detectionstrategies/DET0135#AN0379","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"smtp.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ProcessImageName","description":"Limit to uncommon clients (e.g., scripts or CLI tools using .NET SMTP libraries)"},{"field":"DestPortFilter","description":"Typically 25, 587, 993, 995, or 465 – flag anomalies"},{"field":"AttachmentType","description":"Flag suspicious attachments (e.g., .zip, .7z, .bin)"}],"live":true,"detection_strategies":["DET0135"],"techniques":["T1071.003"]},{"id":"AN0380","stix_id":"x-mitre-analytic--a311af7c-2302-4113-8cc3-d5d599fa908a","name":"Analytic 0380","description":"Detects non-interactive or script-driven email transmission using tools like `sendmail`, `mailx`, or custom SMTP scripts by background processes, especially when sending attachments or large payloads.","url":"https://attack.mitre.org/detectionstrategies/DET0135#AN0380","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"smtp.log, conn.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TransferSizeThreshold","description":"Bytes transferred via SMTP session"},{"field":"ScriptNameFilter","description":"e.g., base64 encoded mailer scripts or one-liners in cron"}],"live":true,"detection_strategies":["DET0135"],"techniques":["T1071.003"]},{"id":"AN0381","stix_id":"x-mitre-analytic--43347e24-50d6-446e-923d-a6fd69805a22","name":"Analytic 0381","description":"Detects email-sending behavior via Terminal, AppleScript, or Automator that interfaces with SMTP or IMAP, typically using curl or mail-related APIs in unsanctioned contexts.","url":"https://attack.mitre.org/detectionstrategies/DET0135#AN0381","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream --predicate 'processImagePath CONTAINS \"curl\" OR \"osascript\"'","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"socket_events","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"UserContext","description":"Monitor non-mail client users initiating SMTP/IMAP"},{"field":"TimeWindow","description":"Look for execution of mail commands during off-hours"}],"live":true,"detection_strategies":["DET0135"],"techniques":["T1071.003"]},{"id":"AN0382","stix_id":"x-mitre-analytic--784b7a50-cdc5-4161-8b52-2be5e5de19ac","name":"Analytic 0382","description":"Detects hosts transmitting large volumes of SMTP, IMAP, or POP3 traffic to external IPs or relays that aren't associated with the enterprise mail infrastructure.","url":"https://attack.mitre.org/detectionstrategies/DET0135#AN0382","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"smtp.log, conn.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ExternalMailRelayFilter","description":"Dest IPs not matching sanctioned SMTP/IMAP relays"},{"field":"OutflowToInflowRatio","description":"Outbound email bytes vastly exceed response"}],"live":true,"detection_strategies":["DET0135"],"techniques":["T1071.003"]}],"live":true,"version":"1.0","techniques":["T1071.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}