Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1114.002

T1114.002Remote Email Collection

T1114.002 — Remote Email Collection is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 12 detection use cases covering it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
12Use cases
0Articles
0Sub-techniques
1Tactic

Use cases covering this technique (12)

Email servers sending high volume traffic to hosts ESCU actions · hunting P O365 Compliance Content Search Exported ESCU actions · alerting P O365 Compliance Content Search Started ESCU actions · alerting P O365 Email Access By Security Administrator ESCU actions · alerting P O365 Email Suspicious Search Behavior ESCU actions · hunting P O365 Mailbox Inbox Folder Shared with All Users ESCU actions · alerting P O365 Mailbox Read Access Granted to Application ESCU actions · alerting P O365 Multiple Mailboxes Accessed via API ESCU actions · alerting P O365 OAuth App Mailbox Access via EWS ESCU actions · alerting P O365 OAuth App Mailbox Access via Graph API ESCU actions · alerting P Hosts receiving high volume of network traffic from email server ESCU actions · hunting P O365 Suspicious Rights Delegation ESCU actions · alerting P