{"id":"T1098.002","name":"Additional Email Delegate Permissions","url":"https://attack.mitre.org/techniques/T1098/002","tactics":["persistence","privilege-escalation"],"platforms":["Windows","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0373","stix_id":"x-mitre-detection-strategy--679edb0f-4fa0-4929-9ffd-881d9f82263d","name":"Detection Strategy for Addition of Email Delegate Permissions","url":"https://attack.mitre.org/detectionstrategies/DET0373","analytics":[{"id":"AN1051","stix_id":"x-mitre-analytic--25bd8222-a9c0-4771-8250-7d6ce7b2d176","name":"Analytic 1051","description":"Detection of anomalous or unauthorized mailbox delegation activity (e.g., Add-MailboxPermission, Default/Anonymous mailbox permissions, Gmail delegation setup).","url":"https://attack.mitre.org/detectionstrategies/DET0373#AN1051","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Add-MailboxPermission, UpdateFolderPermissions","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"DelegatePermissionLevel","description":"Threshold for unexpected delegate roles such as FullAccess or SendAs."},{"field":"FolderTargetScope","description":"Mailbox folder targeted by delegation (Inbox, Root, Calendar, etc.)."},{"field":"DelegatorToDelegatePairing","description":"Pairings of delegate and delegator users that are expected."},{"field":"MailflowAnomalyThreshold","description":"Spike in outbound mail after delegate addition, used to catch phishing or mass exfil."}],"live":true,"detection_strategies":["DET0373"],"techniques":["T1098.002"]},{"id":"AN1052","stix_id":"x-mitre-analytic--42d5a9d5-f897-4c45-b577-9b2c776c6c0d","name":"Analytic 1052","description":"Execution of PowerShell commands that modify mailbox permissions using Exchange cmdlets (e.g., Add-MailboxPermission), often tied to BEC or post-compromise persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0373#AN1052","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"m365:unified","channel":"PowerShell: Add-MailboxPermission","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"PowerShellCmdletFilter","description":"Exchange cmdlets to include or exclude based on scope (e.g., Add-MailboxPermission, Set-MailboxFolderPermission)."},{"field":"ExecutionParent","description":"Flag suspicious script or interactive shell launch by non-admins."},{"field":"TimeWindow","description":"Window in which Add-MailboxPermission is followed by anomalous usage (e.g., SendAs events)."}],"live":true,"detection_strategies":["DET0373"],"techniques":["T1098.002"]}],"live":true,"version":"1.0","techniques":["T1098.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}