Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1114.002

T1114.002Remote Email Collection

T1114.002 — Remote Email Collection is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 13 detection use cases covering it and 1 threat-intel article citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
13Use cases
1Articles
0Sub-techniques
1Tactic

Use cases covering this technique (13)

Email servers sending high volume traffic to hosts ESCU actions · hunting P O365 Compliance Content Search Exported ESCU actions · alerting P O365 Compliance Content Search Started ESCU actions · alerting P O365 Email Access By Security Administrator ESCU actions · alerting P O365 Email Suspicious Search Behavior ESCU actions · hunting P O365 Mailbox Inbox Folder Shared with All Users ESCU actions · alerting P O365 Mailbox Read Access Granted to Application ESCU actions · alerting P O365 Multiple Mailboxes Accessed via API ESCU actions · alerting P O365 OAuth App Mailbox Access via EWS ESCU actions · alerting P O365 OAuth App Mailbox Access via Graph API ESCU actions · alerting P Hosts receiving high volume of network traffic from email server ESCU actions · hunting P O365 Suspicious Rights Delegation ESCU actions · alerting P [LLM] AgentForger rogue-agent C2: inbound TASK-subject email followed by outbound reply to sender domain Bespoke c2 · hunting DSP

Articles citing this technique (1)