{"id":"T1114","name":"Email Collection","url":"https://attack.mitre.org/techniques/T1114","tactics":["collection"],"platforms":["Windows","macOS","Linux","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0476","stix_id":"x-mitre-detection-strategy--2470975e-6748-42a5-9a48-74dc7b687fe9","name":"Email Collection via Local Email Access and Auto-Forwarding Behavior","url":"https://attack.mitre.org/detectionstrategies/DET0476","analytics":[{"id":"AN1309","stix_id":"x-mitre-analytic--4f15b707-9b44-4716-bfcd-e3f28659077b","name":"Analytic 1309","description":"Correlates creation of email forwarding rules or header anomalies (e.g., X-MS-Exchange-Organization-AutoForwarded) with suspicious process execution, file access of .pst/.ost files, and network connections to external SMTP servers.","url":"https://attack.mitre.org/detectionstrategies/DET0476#AN1309","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=5145","data_component":"DC0102","data_component_name":"Network Share Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"WinEventLog:Application","channel":"Exchange logs or header artifacts","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines correlation window across email rule creation and outbound SMTP."},{"field":"UserContext","description":"Filters for admin or service accounts to reduce false positives."},{"field":"SMTPDomainList","description":"Allows tuning based on expected external email domains."}],"live":true,"detection_strategies":["DET0476"],"techniques":["T1114"]},{"id":"AN1310","stix_id":"x-mitre-analytic--ba43428d-b5d2-4815-a614-42ff1ea816a9","name":"Analytic 1310","description":"Detects file access to mbox/maildir files in conjunction with curl/wget/postfix execution, or anomalous shell scripts harvesting user mail directories.","url":"https://attack.mitre.org/detectionstrategies/DET0476#AN1310","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"postfix/smtpd","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"linux-syslog"},{"name":"linux:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"WatchedMailDirs","description":"Specify user mail directories (/var/mail, ~/Maildir)"},{"field":"ProcessNameList","description":"Tune based on local mail clients or curl usage in environment"},{"field":"TimeWindow","description":"Define how close together access and exfil events must occur"}],"live":true,"detection_strategies":["DET0476"],"techniques":["T1114"]},{"id":"AN1311","stix_id":"x-mitre-analytic--ae581308-5c1f-40b9-ae6e-51c375821476","name":"Analytic 1311","description":"Monitors Mail.app database or maildir file access, automation via AppleScript, and abnormal mail rule creation using scripting or UI automation frameworks.","url":"https://attack.mitre.org/detectionstrategies/DET0476#AN1311","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Mail or AppleScript subsystem","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"es_event_open, es_event_exec","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-endpointsecurity"}],"mutable_elements":[{"field":"ScriptProcessNameList","description":"Script interpreters or automation tools (osascript, Automator, etc.)"},{"field":"WatchedMailFiles","description":"Mail.app SQLite DB or .emlx directory"}],"live":true,"detection_strategies":["DET0476"],"techniques":["T1114"]},{"id":"AN1312","stix_id":"x-mitre-analytic--2faaefb9-7816-4eb5-a9f5-b4006c99c20b","name":"Analytic 1312","description":"Correlates unusual auto-forwarding rule creation via Exchange Web Services or Outlook rules engine, presence of X-MS-Exchange-Organization-AutoForwarded headers, and logon session anomalies from abnormal IPs.","url":"https://attack.mitre.org/detectionstrategies/DET0476#AN1312","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Set-Mailbox, New-InboxRule","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"m365-unified"},{"name":"m365:exchange","channel":"MessageTrace logs","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-exchange"},{"name":"azure:ad","channel":"SignInEvents","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"azure-ad"}],"mutable_elements":[{"field":"UserAgentList","description":"Restrict rules from non-browser agents"},{"field":"ExternalSMTPDomainList","description":"Allow listing for org-sanctioned forwarding domains"},{"field":"TimeWindow","description":"Time delta between rule creation and suspicious sign-in"}],"live":true,"detection_strategies":["DET0476"],"techniques":["T1114"]}],"live":true,"version":"1.0","techniques":["T1114"]}],"sigma_rules":[{"id":"18b88d08-d73e-4f21-bc25-4b9892a4fdd0","title":"PST Export Alert Using eDiscovery Alert","author":"Sorina Ionescu","status":"test","level":"medium","date":"2022-02-08","modified":"2022-11-17","description":"Alert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content","references":["https://learn.microsoft.com/en-us/microsoft-365/compliance/alert-policies?view=o365-worldwide"],"logsource":{"product":"m365","service":"threat_management"},"tags":["attack.collection","attack.t1114"],"path":"rules/cloud/m365/threat_management/microsoft365_pst_export_alert.yml","techniques":["T1114"],"cves":[]},{"id":"24549159-ac1b-479c-8175-d42aea947cae","title":"Hacktool Ruler","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-05-31","modified":"2022-10-09","description":"This events that are generated when using the hacktool Ruler by Sensepost","references":["https://github.com/sensepost/ruler","https://github.com/sensepost/ruler/issues/47","https://github.com/staaldraad/go-ntlm/blob/cd032d41aa8ce5751c07cb7945400c0f5c81e2eb/ntlm/ntlmv1.go#L427","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4776","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/event-4624"],"logsource":{"product":"windows","service":"security"},"tags":["attack.discovery","attack.execution","attack.collection","attack.lateral-movement","attack.t1087","attack.t1114","attack.t1059","attack.t1550.002"],"path":"rules/windows/builtin/security/win_security_alert_ruler.yml","techniques":["T1087","T1114","T1059","T1550.002"],"cves":[]},{"id":"25676e10-2121-446e-80a4-71ff8506af47","title":"Exchange PowerShell Snap-Ins Usage","author":"FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-03-03","modified":"2023-03-24","description":"Detects adding and using Exchange PowerShell snap-ins to export mailbox data. As seen used by HAFNIUM and APT27","references":["https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/","https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/","https://www.intrinsec.com/apt27-analysis/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1059.001","attack.collection","attack.t1114"],"path":"rules/windows/process_creation/proc_creation_win_powershell_snapins_hafnium.yml","techniques":["T1059.001","T1114"],"cves":[]},{"id":"6897cd82-6664-11ed-9022-0242ac120002","title":"PST Export Alert Using New-ComplianceSearchAction","author":"Nikita Khalimonenkov","status":"test","level":"medium","date":"2022-11-17","modified":null,"description":"Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.","references":["https://learn.microsoft.com/en-us/powershell/module/exchange/new-compliancesearchaction?view=exchange-ps"],"logsource":{"product":"m365","service":"threat_management"},"tags":["attack.collection","attack.t1114"],"path":"rules/cloud/m365/threat_management/microsoft365_pst_export_alert_using_new_compliancesearchaction.yml","techniques":["T1114"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-42009","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2024-27443","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2020-0688","state":"mapped","mapping_types":["primary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}