{"id":"T1114.001","name":"Local Email Collection","url":"https://attack.mitre.org/techniques/T1114/001","tactics":["collection"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0047","stix_id":"x-mitre-detection-strategy--8fb1967e-478f-4a83-9fb9-3da1015b8a26","name":"Detect Local Email Collection via Outlook Data File Access and Command Line Tooling","url":"https://attack.mitre.org/detectionstrategies/DET0047","analytics":[{"id":"AN0130","stix_id":"x-mitre-analytic--11cd0577-97e6-4def-a86b-fe167ae4e33d","name":"Analytic 0130","description":"Detection focuses on processes that attempt to locate, access, or exfiltrate local Outlook data files (.pst/.ost) using file system access, native Windows utilities (e.g., PowerShell, WMI), or remote access tools with file browsing capabilities. The behavior chain includes directory enumeration, file access, optional compression or staging, and network transfer.","url":"https://attack.mitre.org/detectionstrategies/DET0047#AN0130","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TargetFilePathPattern","description":"Regex or wildcard patterns for sensitive Outlook file paths (.ost/.pst) depending on organizational deployment."},{"field":"TimeWindow","description":"Timeframe used to correlate related file access, process creation, and exfiltration events."},{"field":"UserContext","description":"Limit detection to user accounts not normally interacting with Outlook file locations (e.g., service accounts, low-privileged users)."},{"field":"ProcessAllowList","description":"Filter known legitimate Outlook-accessing processes to reduce false positives."}],"live":true,"detection_strategies":["DET0047"],"techniques":["T1114.001"]}],"live":true,"version":"1.0","techniques":["T1114.001"]}],"sigma_rules":[{"id":"2837e152-93c8-43d2-85ba-c3cd3c2ae614","title":"Powershell Local Email Collection","author":"frack113","status":"test","level":"medium","date":"2021-07-21","modified":"2022-12-25","description":"Adversaries may target user email on local systems to collect sensitive information.\nFiles containing email data can be acquired from a users local system, such as Outlook storage or cache files.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1114.001/T1114.001.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.collection","attack.t1114.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_mail_acces.yml","techniques":["T1114.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}