kevmap

Techniques › T1114

T1114 Email Collection

collection — Windows, macOS, Linux, Office Suite · attack.mitre.org · JSON

1
MITRE detection strategy
4
analytics
4
Sigma rules tagged attack.t1114
3
KEV CVEs mapped here
<p>Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2024-42009Roundcube Webmail primary impact Mapped2025-06-09
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) primary impact Mapped2025-05-19
CVE-2020-0688Microsoft Exchange Server primary impact Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1114

Author: Sorina Ionescu · 2022-02-08 (modified 2022-11-17) · logsource: product=m365 service=threat_management · 18b88d08-d73e-4f21-bc25-4b9892a4fdd0
Alert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content
Techniques: T1114
Author: Florian Roth (Nextron Systems) · 2017-05-31 (modified 2022-10-09) · logsource: product=windows service=security · 24549159-ac1b-479c-8175-d42aea947cae
This events that are generated when using the hacktool Ruler by Sensepost
Author: FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems) · 2021-03-03 (modified 2023-03-24) · logsource: product=windows category=process_creation · 25676e10-2121-446e-80a4-71ff8506af47
Detects adding and using Exchange PowerShell snap-ins to export mailbox data. As seen used by HAFNIUM and APT27
Techniques: T1059.001T1114
Author: Nikita Khalimonenkov · 2022-11-17 · logsource: product=m365 service=threat_management · 6897cd82-6664-11ed-9022-0242ac120002
Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.
Techniques: T1114

Sub-techniques

IDNameSigma rulesKEV CVEs
T1114.001Local Email Collection10
T1114.002Remote Email Collection01
T1114.003Email Forwarding Rule60