{"id":"T1114.002","name":"Remote Email Collection","url":"https://attack.mitre.org/techniques/T1114/002","tactics":["collection"],"platforms":["Office Suite","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0048","stix_id":"x-mitre-detection-strategy--00a515dc-e3be-4349-9c61-65a5c0ce815d","name":"Detect Remote Email Collection via Abnormal Login and Programmatic Access","url":"https://attack.mitre.org/detectionstrategies/DET0048","analytics":[{"id":"AN0131","stix_id":"x-mitre-analytic--c42179a8-71c5-41ba-bbfa-d6c1a93e729b","name":"Analytic 0131","description":"Detects adversaries accessing remote mail systems (e.g., Exchange Online, O365) using stolen credentials or OAuth tokens, followed by scripted access to mailbox contents via PowerShell, AADInternals, or unattended API queries. Detection focuses on abnormal logon sessions, user agents, IP locations, and scripted or tool-based email data access.","url":"https://attack.mitre.org/detectionstrategies/DET0048#AN0131","platforms":["Windows"],"log_source_references":[{"name":"azure:signinlogs","channel":"Abnormal sign-in from scripting tools (PowerShell, AADInternals)","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"azure-signinlogs"},{"name":"m365:purview","channel":"MailItemsAccessed & Exchange Audit","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-purview"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"UserAgentPattern","description":"Filters user agents like 'PowerShell', 'AADInternals', 'python-requests' which can vary depending on script/tool."},{"field":"TimeWindow","description":"Defines the temporal correlation window between login, command execution, and outbound email access."},{"field":"KnownIPLocations","description":"Defines baseline geo/IP address ranges to suppress known corporate access."},{"field":"PrivilegedUserList","description":"Defines the accounts considered privileged (admin, execs) and worthy of tighter thresholds."}],"live":true,"detection_strategies":["DET0048"],"techniques":["T1114.002"]},{"id":"AN0132","stix_id":"x-mitre-analytic--3af413c2-5b26-4f43-b198-11b4dce97a0a","name":"Analytic 0132","description":"Monitors programmatic access to user mailboxes in cloud-based email systems (e.g., O365, Exchange Online) using APIs or tokens. Focuses on OAuth misuse, suspicious MailItemsAccessed patterns, scripted keyword searches, and connections from untrusted agents or locations.","url":"https://attack.mitre.org/detectionstrategies/DET0048#AN0132","platforms":["Office Suite"],"log_source_references":[{"name":"m365:purview","channel":"MailItemsAccessed, Search-Mailbox events","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-purview"},{"name":"azure:signinlogs","channel":"Suspicious login to cloud mailbox system","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"azure-signinlogs"},{"name":"m365:unified","channel":"Search-Mailbox, Get-MessageTrace, eDiscovery requests","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"MailAccessVolumeThreshold","description":"Number of emails accessed within time window to flag anomaly."},{"field":"OAuthClientIDAllowList","description":"Allows tuning based on known app registrations."},{"field":"KeywordSearchFrequency","description":"Flag high volumes of message searches using suspicious patterns."},{"field":"LoginGeolocationVariance","description":"Trigger when IP geolocation varies significantly from user's historical profile."}],"live":true,"detection_strategies":["DET0048"],"techniques":["T1114.002"]}],"live":true,"version":"1.0","techniques":["T1114.002"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2012-0767","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}