Techniques › T1114
T1114 Email Collection
collection — Windows, macOS, Linux, Office Suite · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
4
Sigma rules tagged attack.t1114
3
KEV CVEs mapped here
<p>Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2024-42009 | Roundcube Webmail | primary impact | Mapped | 2025-06-09 |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | primary impact | Mapped | 2025-05-19 |
| CVE-2020-0688 | Microsoft Exchange Server | primary impact | Mapped | 2021-11-03 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0476 Email Collection via Local Email Access and Auto-Forwarding Behavior v1.0
AN1309 WindowsCorrelates creation of email forwarding rules or header anomalies (e.g., X-MS-Exchange-Organization-AutoForwarded) with suspicious process execution, file access of .pst/.ost files, and network connections to external SMTP servers.Tunable:
TimeWindowUserContextSMTPDomainListAN1310 LinuxDetects file access to mbox/maildir files in conjunction with curl/wget/postfix execution, or anomalous shell scripts harvesting user mail directories.Tunable:WatchedMailDirsProcessNameListTimeWindowAN1311 macOSMonitors Mail.app database or maildir file access, automation via AppleScript, and abnormal mail rule creation using scripting or UI automation frameworks.Tunable:ScriptProcessNameListWatchedMailFilesAN1312 Office SuiteCorrelates unusual auto-forwarding rule creation via Exchange Web Services or Outlook rules engine, presence of X-MS-Exchange-Organization-AutoForwarded headers, and logon session anomalies from abnormal IPs.Tunable:UserAgentListExternalSMTPDomainListTimeWindow
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1114
Author: Sorina Ionescu
· 2022-02-08 (modified 2022-11-17) · logsource: product=m365 service=threat_management · 18b88d08-d73e-4f21-bc25-4b9892a4fdd0
Alert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content
Author: Florian Roth (Nextron Systems)
· 2017-05-31 (modified 2022-10-09) · logsource: product=windows service=security · 24549159-ac1b-479c-8175-d42aea947cae
This events that are generated when using the hacktool Ruler by Sensepost
Author: FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems)
· 2021-03-03 (modified 2023-03-24) · logsource: product=windows category=process_creation · 25676e10-2121-446e-80a4-71ff8506af47
Detects adding and using Exchange PowerShell snap-ins to export mailbox data. As seen used by HAFNIUM and APT27
Author: Nikita Khalimonenkov
· 2022-11-17 · logsource: product=m365 service=threat_management · 6897cd82-6664-11ed-9022-0242ac120002
Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.