{"id":"T1684.001","name":"Impersonation","url":"https://attack.mitre.org/techniques/T1684/001","tactics":["stealth"],"platforms":["Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0286","stix_id":"x-mitre-detection-strategy--1e08be7e-451c-4b10-9e65-b6dbf8d54b38","name":"Detection Strategy for Impersonation","url":"https://attack.mitre.org/detectionstrategies/DET0286","analytics":[{"id":"AN0792","stix_id":"x-mitre-analytic--e4246c20-fbe4-4750-a29e-44e3fe179bf2","name":"Analytic 0792","description":"Monitor for anomalous email activity originating from Windows-hosted applications (e.g., Outlook) where the sending account name or display name does not match the underlying SMTP address. Detect abnormal volume of outbound messages containing sensitive keywords (e.g., 'payment', 'wire transfer') or anomalous login locations for accounts associated with email sending activity.","url":"https://attack.mitre.org/detectionstrategies/DET0286#AN0792","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"m365:unified","channel":"SendOnBehalf/SendAs: Emails sent where the sending identity mismatches account ownership","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"KeywordList","description":"Adjust impersonation detection keywords based on local business risk terms (e.g., 'ACH', 'Invoice')."},{"field":"GeoLocationBaseline","description":"Define trusted geographic regions for normal user email activity."}],"live":true,"detection_strategies":["DET0286"],"techniques":["T1684.001"]},{"id":"AN0793","stix_id":"x-mitre-analytic--5c7a8194-f0cb-498a-98c6-5928859bf79f","name":"Analytic 0793","description":"Monitor mail server logs (Postfix, Sendmail, Exim) for anomalous From headers mismatching authenticated SMTP identities. Detect abnormal relay attempts, spoofed envelope-from values, or large-scale outbound campaigns targeting internal users.","url":"https://attack.mitre.org/detectionstrategies/DET0286#AN0793","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Processes executing sendmail/postfix with forged headers","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"Application:Mail","channel":"Mismatch between authenticated username and From header in email","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"application-mail"}],"mutable_elements":[{"field":"KnownRelayHosts","description":"Filter trusted relays or automated notification systems from impersonation alerts."}],"live":true,"detection_strategies":["DET0286"],"techniques":["T1684.001"]},{"id":"AN0794","stix_id":"x-mitre-analytic--1305f37f-8333-4d86-9714-340b66c65771","name":"Analytic 0794","description":"Monitor Mail.app activity or unified logs for anomalous SMTP usage, including mismatches between display name and authenticated AppleID or Exchange credentials. Detect use of third-party mail utilities that attempt to send on behalf of corporate identities.","url":"https://attack.mitre.org/detectionstrategies/DET0286#AN0794","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Mail.app or third-party clients sending messages with mismatched From headers","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"TrustedMailClients","description":"Allowlist known third-party clients used for legitimate email activity."}],"live":true,"detection_strategies":["DET0286"],"techniques":["T1684.001"]},{"id":"AN0795","stix_id":"x-mitre-analytic--2266c86a-a47e-46ac-aa6d-c1eb6d49a1e5","name":"Analytic 0795","description":"Monitor SaaS mail platforms (Google Workspace, M365, Okta-integrated apps) for SendAs/SendOnBehalfOf operations where the delegated permissions are unusual or newly granted. Detect impersonation attempts where adversaries configure rules to auto-forward or auto-reply with impersonated content.","url":"https://attack.mitre.org/detectionstrategies/DET0286#AN0795","platforms":["SaaS"],"log_source_references":[{"name":"gcp:workspaceaudit","channel":"SendAs: Outbound messages with alias identities that differ from primary account","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"gcp-workspaceaudit"}],"mutable_elements":[{"field":"DelegationBaseline","description":"Maintain baseline of normal SendAs/SendOnBehalf relationships to reduce false positives."}],"live":true,"detection_strategies":["DET0286"],"techniques":["T1684.001"]},{"id":"AN0796","stix_id":"x-mitre-analytic--250d2977-7b94-4041-a299-0f2f1532eb95","name":"Analytic 0796","description":"Monitor Office Suite applications (Outlook, Word mail merge, Excel macros) for abnormal automated message sending, especially when macros or scripts trigger email delivery. Detect patterns of impersonation language (urgent, payment, executive request) combined with anomalous execution of Office macros.","url":"https://attack.mitre.org/detectionstrategies/DET0286#AN0796","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"SendOnBehalf/SendAs: Office Suite initiated messages using impersonated identities","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"MacroExecutionThreshold","description":"Threshold for correlating macro execution with email sending activity."}],"live":true,"detection_strategies":["DET0286"],"techniques":["T1684.001"]}],"live":true,"version":"1.0","techniques":["T1684.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}