Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1114.003

T1114.003Email Forwarding Rule

T1114.003 — Email Forwarding Rule is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 14 detection use cases covering it and 4 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
14Use cases
4Articles
0Sub-techniques
1Tactic

Use cases covering this technique (14)

Google Workspace email auto-forwarding to external domain Internal actions · alerting DD M365 mail-forwarding rule created Internal actions · alerting DD O365 Email New Inbox Rule Created ESCU actions · hunting P O365 Email Suspicious Behavior Alert ESCU actions · alerting P O365 Email Transport Rule Changed ESCU actions · hunting P O365 Mailbox Email Forwarding Enabled ESCU actions · alerting P O365 New Email Forwarding Rule Created ESCU actions · alerting P O365 New Email Forwarding Rule Enabled ESCU actions · alerting P O365 Suspicious Admin Email Forwarding ESCU actions · hunting P O365 Suspicious User Email Forwarding ESCU actions · hunting P [LLM] Email-hiding inbox rules created post-compromise (BEC / mailbox concealment) Bespoke actions · hunting DSΣP [LLM] Post-compromise M365 defense-evasion inbox rule creation (UAT-11764 mailbox takeover) Bespoke actions · hunting DSΣ [LLM] Post-device-code malicious inbox rule creation (BEC prep) Bespoke actions · alerting DSP [LLM] Outbound email BCC'd to giftshop.club exfil domain (postmark-mcp backdoor) Bespoke actions · alerting DSΣPDD

Articles citing this technique (4)