Email Collection T1114

Tactic: Collection

Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.

Events covered

8 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 69 rules share fields, values, and exclusions.

Fields filtered most (117 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Operation27eq 20, in 6, starts_with 2, contains 1, ends_with 1new-inboxrule, harddelete, mailitemsaccessed, set-inboxrule, new-transportrule
sourcetype21eq 21, in 3o365:management:activity, ms:o365:reporting:messagetrace, o365:reporting:messagetrace
Workload16eq 16exchange, securitycompliancecenter
EventType6eq 4, in 2mailitemsaccessed, New-InboxRule, New-TransportRule, Set-InboxRule, change_application_setting
ScriptBlockText6contains 3, in 3, eq 1*invoke-addgmailrule*, *invoke-domainharvestowa*, *invoke-globalmailsearch*, -comobject outlook.application, -filepath
EventID5eq 4, in 14104, 4103, 4688, compliancedlmexchange, compliancedlmsharepoint
data_stream.dataset5eq 5o365.audit, azure.graphactivitylogs, google_workspace.admin
m365::Workload5eq 5exchange, Exchange
CommandLine4contains 2, match 1, regex_match 1, wildcard 1$exserver=Get-ExchangeServer..., (?i)-FilePath.{1,}\.pst, *-Mailbox*-ContentFilter*, *MailboxExportRequest*, -encodedcommand
Name4eq 2, in 2blindcopyto, redirectmessageto, ediscovery search started or exported, email sending limit exceeded, suspicious email forwarding activity
Provider_Name4eq 4exchange, Exchange
event.category4eq 4process, web
host.os.type4eq 4
m365::Parameters4contains 4forwardingsmtpaddress, forwardto, redirectto, deletemessage, forwardasattachmentto
match14ge 40

Top indicator values (306 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
sourcetypeeq
o365:management:activity
2180
Workloadeq
exchange
1220
Workloadeq
securitycompliancecenter
48
Operationeq
mailitemsaccessed
44
Operationeq
harddelete
34
Operationeq
new-inboxrule
35
Operationeq
set-inboxrule
33
Operationin
set-transportrule
44
match1ge
0
44
match2ge
0
44
AppIdeq
*
33
AppIdeq
00000003-0000-0000-c000-000000000000
22
Provider_Nameeq
exchange
317
data_stream.dataseteq
o365.audit
347
event.outcomeeq
success
3369
event.typeeq
start
31078
m365::Folder.Pathin
\\recoverable items\\deletions
34
m365::Folder.Pathin
\\sent items
34
m365::Parameterscontains
forwardingsmtpaddress
33
m365::Parameterscontains
forwardto
33
m365::Parameterscontains
redirectto
33
m365::Workloadeq
exchange
36
match3ge
0
33
process_nameeq
powershell.exe
3184
process_nameeq
pwsh.exe
377
sourcetypein
ms:o365:reporting:messagetrace
34
sourcetypein
o365:reporting:messagetrace
34
ClientAppIdeq
*
22
DistinctUserCountgt
1
22
EventIDeq
4104
2269

Exclusions (167 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
usercontains
devilfish-applicationaccount
2
usercontains
nt authority\system (microsoft.exchange.servicehost)
2
usercontains
nt authority\system (w3wp)
2
CommandLinematch
$exserver=Get-ExchangeServer ([Environment]::MachineName) -ErrorVariable...
1
EventDatacontains
gc_service.exe
1
EventDatacontains
gc_worker.exe
1
Imageeq
?:\windows\system32\windowspowershell\v1.0\powershell.exe
1
Operationin
add-mailboxpermission
1
Operationin
set-mailbox
1
ParentImagecontains
gc_service.exe
1
ParentImagecontains
gc_worker.exe
1
ParentImageeq
?:\program files (x86)\cybercnsagent\cybercnsagent.exe
1
ParentImageeq
c:\windows\system32\msiexec.exe
1
TargetFilenamein
c:\\users\\*\\appdata\\local\\microsoft\\outlook*
1
TargetFilenamein
c:\\users\\*\\my documents\\outlook files\\*
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 11 rules

Elastic 13 rules

Splunk 26 rules

Kusto 16 rules

Panther 3 rules