{"id":"T1684.002","name":"Email Spoofing","url":"https://attack.mitre.org/techniques/T1684/002","tactics":["stealth"],"platforms":["Linux","macOS","Office Suite","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0431","stix_id":"x-mitre-detection-strategy--6dec9c28-6dcb-4470-ad69-6cdb520adb53","name":"Detection Strategy for Email Spoofing","url":"https://attack.mitre.org/detectionstrategies/DET0431","analytics":[{"id":"AN1202","stix_id":"x-mitre-analytic--c0055eb3-5579-48a8-b9d3-df6dd67bc388","name":"Analytic 1202","description":"Monitor email message traces and headers for failed SPF, DKIM, or DMARC checks indicating spoofed sender identities. Correlate abnormal sender domains or mismatched return-paths with elevated spoofing likelihood.","url":"https://attack.mitre.org/detectionstrategies/DET0431#AN1202","platforms":["Windows"],"log_source_references":[{"name":"m365:messagetrace","channel":"AuthenticationDetails=fail OR SPF=fail OR DKIM=fail OR DMARC=fail","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-messagetrace"}],"mutable_elements":[{"field":"SpoofScoreThreshold","description":"Defines sensitivity to SPF/DKIM/DMARC failures; higher thresholds reduce false positives but may miss stealthier spoofing."},{"field":"MonitoredDomains","description":"Specifies which domains to enforce strict validation against; enterprise-specific tuning may be required."}],"live":true,"detection_strategies":["DET0431"],"techniques":["T1684.002"]},{"id":"AN1203","stix_id":"x-mitre-analytic--38300670-8c96-4f80-bc1b-d69242023a20","name":"Analytic 1203","description":"Detects spoofed emails by analyzing mail server logs (e.g., Postfix, Sendmail) for mismatched header fields, failed SPF/DKIM checks, and anomalies in SMTP proxy logs. Defender observes discrepancies between sending domain, return-path domain, and message metadata.","url":"https://attack.mitre.org/detectionstrategies/DET0431#AN1203","platforms":["Linux"],"log_source_references":[{"name":"linux:syslog","channel":"SPF fail OR DKIM fail OR DMARC fail OR mismatched from_domain vs return_path_domain","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"SenderDomainWhitelist","description":"Defines approved sender domains to suppress alerts for expected mismatches, reducing false positives."},{"field":"TimeWindow","description":"Sets correlation period for repeated spoofing attempts to flag campaigns vs. isolated misconfigurations."}],"live":true,"detection_strategies":["DET0431"],"techniques":["T1684.002"]},{"id":"AN1204","stix_id":"x-mitre-analytic--0c4a2cfd-a064-4f45-9c07-eb5c1044dd61","name":"Analytic 1204","description":"Detects suspicious inbound mail traffic where SPF/DKIM/DMARC authentication fails or where sender and return-path domains mismatch, observable in Apple Mail unified logs or MDM-controlled logging pipelines.","url":"https://attack.mitre.org/detectionstrategies/DET0431#AN1204","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"SPF fail OR DKIM fail OR DMARC fail OR mismatched header vs envelope domains","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"RecipientSensitivity","description":"Allows tuning based on which users (e.g., executives, finance staff) receive stricter spoofing detection policies."},{"field":"HeaderMismatchTolerance","description":"Defines tolerance for minor discrepancies in domain alignment, balancing detection with usability."}],"live":true,"detection_strategies":["DET0431"],"techniques":["T1684.002"]},{"id":"AN1205","stix_id":"x-mitre-analytic--e7a0e155-e0bc-45b5-b0ef-98ec4f5eea63","name":"Analytic 1205","description":"Correlates Office 365 or Google Workspace audit logs for spoofed sender addresses, failed email authentication, and anomalies in message delivery metadata. Defender observes failed SPF/DKIM checks and domain mismatches tied to suspicious campaigns.","url":"https://attack.mitre.org/detectionstrategies/DET0431#AN1205","platforms":["Office Suite"],"log_source_references":[{"name":"saas:email","channel":"AuthenticationFailures (SPF/DKIM/DMARC) OR Domain Mismatch","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-email"}],"mutable_elements":[{"field":"MessageVolumeThreshold","description":"Defines thresholds for spoofed messages volume before alerts trigger, reducing noise for isolated misconfigs."},{"field":"TargetedUserGroups","description":"Restricts higher-sensitivity detection to high-value groups (executives, admins, finance) for efficiency."}],"live":true,"detection_strategies":["DET0431"],"techniques":["T1684.002"]}],"live":true,"version":"1.0","techniques":["T1684.002"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}