Techniques › T1684.002 › AN1205
AN1205 Analytic 1205
Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Correlates Office 365 or Google Workspace audit logs for spoofed sender addresses, failed email authentication, and anomalies in message delivery metadata. Defender observes failed SPF/DKIM checks and domain mismatches tied to suspicious campaigns.</p>
- Detects
- T1684.002 Email Spoofing
- Part of
- DET0431 Detection Strategy for Email Spoofing
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| saas:email | AuthenticationFailures (SPF/DKIM/DMARC) OR Domain Mismatch | DC0038 Application Log Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
MessageVolumeThreshold | Defines thresholds for spoofed messages volume before alerts trigger, reducing noise for isolated misconfigs. |
TargetedUserGroups | Restricts higher-sensitivity detection to high-value groups (executives, admins, finance) for efficiency. |