{"id":"T1667","name":"Email Bombing","url":"https://attack.mitre.org/techniques/T1667","tactics":["impact"],"platforms":["Linux","Office Suite","Windows","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0355","stix_id":"x-mitre-detection-strategy--9a66295a-9f47-47a8-bda4-935cd311186a","name":"Detection Strategy for Email Bombing","url":"https://attack.mitre.org/detectionstrategies/DET0355","analytics":[{"id":"AN1008","stix_id":"x-mitre-analytic--1f515cf2-91a5-4bed-95a1-ed8fc8b24a87","name":"Analytic 1008","description":"Detect abnormally high volume of inbound email messages or repetitive attachments being delivered to a single mailbox within a short time window. Defenders should look for anomalous spikes in message counts and repetitive attachment file creation events correlated with targeted users.","url":"https://attack.mitre.org/detectionstrategies/DET0355#AN1008","platforms":["Windows"],"log_source_references":[{"name":"m365:unified","channel":"Send/Receive: Unusual spikes in inbound messages to a single recipient","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines the aggregation interval (e.g., 5 minutes, 1 hour) for detecting spikes in inbound email traffic."},{"field":"RecipientThreshold","description":"Defines maximum number of acceptable messages per user before triggering anomaly."},{"field":"AttachmentSizeThreshold","description":"Defines the size threshold for repetitive attachments to be flagged."}],"live":true,"detection_strategies":["DET0355"],"techniques":["T1667"]},{"id":"AN1009","stix_id":"x-mitre-analytic--31e4c4dc-3094-45b2-9d4d-1b0bf8311498","name":"Analytic 1009","description":"Monitor mail server logs (e.g., Postfix, Sendmail) for excessive connections or inbound message counts targeting a single recipient. Correlate with repetitive attachment storage in /var/mail or /var/spool/mail directories.","url":"https://attack.mitre.org/detectionstrategies/DET0355#AN1009","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"File creation events in /var/mail or /var/spool/mail exceeding baseline thresholds","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"Application:Mail","channel":"High-frequency inbound mail activity to a specific recipient address","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"application-mail"}],"mutable_elements":[{"field":"MailVolumeThreshold","description":"Tunable value for the maximum acceptable emails per minute per user."},{"field":"AttachmentPatternList","description":"List of suspicious attachment extensions that may be abused for repetitive delivery."}],"live":true,"detection_strategies":["DET0355"],"techniques":["T1667"]},{"id":"AN1010","stix_id":"x-mitre-analytic--7e9cb99b-4040-4b73-bd70-1bd68ae0f373","name":"Analytic 1010","description":"Detect abnormal use of email clients (e.g., Outlook, Thunderbird) showing mass arrival of messages or repetitive attachments being locally stored. Correlate message volume with file creation activity in mail cache directories.","url":"https://attack.mitre.org/detectionstrategies/DET0355#AN1010","platforms":["Office Suite"],"log_source_references":[{"name":"m365:exchange","channel":"MailDelivery: High-frequency delivery of messages or attachments to a single recipient","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-exchange"}],"mutable_elements":[{"field":"UserContext","description":"Context for distinguishing between VIP or sensitive recipients and general users."}],"live":true,"detection_strategies":["DET0355"],"techniques":["T1667"]},{"id":"AN1011","stix_id":"x-mitre-analytic--d41cdfc1-2a82-4442-a1ca-177fe59b8dff","name":"Analytic 1011","description":"Monitor unified logs and Mail.app activity for repetitive incoming messages with attachments. Defenders should look for large volumes of incoming mail stored under ~/Library/Mail with unusual timing or repetitive subjects.","url":"https://attack.mitre.org/detectionstrategies/DET0355#AN1011","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Repetitive inbound email delivery activity logged within a short time window","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"create: Attachment file creation in ~/Library/Mail directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"fs-fsusage"}],"mutable_elements":[{"field":"FileCountThreshold","description":"Threshold for repetitive attachment files created within a defined interval."}],"live":true,"detection_strategies":["DET0355"],"techniques":["T1667"]}],"live":true,"version":"1.0","techniques":["T1667"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}