FORENSIA

ATT&CK · T1114.002 · sub-technique

Remote Email Collection

Tactics: collection

About

Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.

Platforms: Office Suite, WindowsParent: T1114 Email CollectionMITRE ATT&CK ↗

Corpus indicators tagged with this technique

37 indicators in the corpus carry T1114.002.

IndicatorTypeFamilySevSrc
fcd1b654a0b3e8f85ca7cfdafe494d4bmd5phishing761
22aaeb4946ba6d2f2e27feb7dbb295demd5761
3432dd9ac0df80ef86eb80bd080f839bmd5761
3d3a621f852c42d97fd7260681e42508md5761
a7d7d6c4c3f227f7117261c63b9e23a9md5761
28cb7b261f4eb97e8a4b3b0d32f8def1md5761
1ab58838e5790efb22f2d35ab98c0b7dmd5761
bae82a15d1dbfb024617b9b56a8e5f66md5761
f169d6d172dfb775895a5e2b1540c854md5761
f61fbfb7aa1cd5dc8f70b055b51563e2md5761
9f5f2f0fb0a7f5aa9f16b9a7b6dad89fmd5761
138.226.246.94ipsupply_chain705
41.128.0.142ipphishing701
ilersls.orgdomainphishing651
aaalen.dedomainphishing651
trisrnareprjdocz.comdomainphishing651
theoceanac.onlinedomainphishing651
crm-technik.dedomainphishing651
klenpare.comdomainphishing651
dufllot.sbsdomainphishing651
uvarnix.cfddomainphishing651
xavon.sbsdomainphishing651
enerdizerandtron.dedomainphishing651
smartcontrolengineer.comdomainphishing651
razen.onlinedomainphishing651
2fuserinfo.emaildomain651
jumpast.esdomainphishing651
buenne.dedomainphishing651
ihrsupportcenter.dedomainphishing651
rundwasser.dedomainphishing651

Showing the top 30 by severity of 37.