kevmap

TechniquesT1589 › T1589.002

T1589.002 Email Addresses

reconnaissance — PRE · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
1
Sigma rules tagged attack.t1589.002
0
KEV CVEs mapped here
<p>Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email infrastructure and addresses for employees.</p><p>Adversaries may easily gather email addresses, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Email addresses could also be enumerated via more active means (i.e. Active Scanning), such as probing and analyzing responses from authentication services that may reveal valid usernames in a system. For example, adversaries may be able to enumerate email addresses in Office 365 environments by querying a variety of publicly available API endpoints, such as autodiscover and GetCredentialType.</p><p>Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Email Accounts), and/or initial access (ex: Phishing or Brute Force via External Remote Services).</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1589.002

Author: frack113 · 2025-03-05 · logsource: product=windows category=ps_script · cdfa73b6-3c9d-4bb8-97f8-ddbd8921f5c5
Detects the use of the "Get-ADComputer" cmdlet in order to identify systems which are configured for unconstrained delegation.

Rules tagged at the parent level (attack.t1589) 2

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-03 · logsource: product=azure service=riskdetection · 19128e5e-4743-48dc-bd97-52e5775af817
Indicates that the user's valid credentials have been leaked.
Techniques: T1589
Author: Florian Roth (Nextron Systems) · 2017-08-24 (modified 2021-11-27) · logsource: product=linux service=sshd · 4c9d903d-4939-4094-ade0-3cb748f4d7da
Detects exploitation attempt using public exploit code for CVE-2018-15473
Techniques: T1589
CVE tags: CVE-2018-15473