kevmap

TechniquesT1114 › T1114.002

T1114.002 Remote Email Collection

collection — Office Suite, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
2
analytics
0
Sigma rules tagged attack.t1114.002
1
KEV CVEs mapped here
<p>Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2012-0767Adobe Flash Player secondary impact Mapped2022-06-08

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1114.002

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content. 1 actively exploited CVE maps here.

Rules tagged at the parent level (attack.t1114) 4

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Sorina Ionescu · 2022-02-08 (modified 2022-11-17) · logsource: product=m365 service=threat_management · 18b88d08-d73e-4f21-bc25-4b9892a4fdd0
Alert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content
Techniques: T1114
Author: Florian Roth (Nextron Systems) · 2017-05-31 (modified 2022-10-09) · logsource: product=windows service=security · 24549159-ac1b-479c-8175-d42aea947cae
This events that are generated when using the hacktool Ruler by Sensepost
Author: FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems) · 2021-03-03 (modified 2023-03-24) · logsource: product=windows category=process_creation · 25676e10-2121-446e-80a4-71ff8506af47
Detects adding and using Exchange PowerShell snap-ins to export mailbox data. As seen used by HAFNIUM and APT27
Techniques: T1059.001T1114
Author: Nikita Khalimonenkov · 2022-11-17 · logsource: product=m365 service=threat_management · 6897cd82-6664-11ed-9022-0242ac120002
Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.
Techniques: T1114