Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1114.003

T1114.003Email Forwarding Rule

T1114.003 — Email Forwarding Rule is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 14 detection use cases covering it and 4 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
14Use cases
4Articles
0Sub-techniques
1Tactic

Use cases covering this technique (14)

Google Workspace email auto-forwarding to external domain Internal actions · alerting DD M365 mail-forwarding rule created Internal actions · alerting DD O365 Email New Inbox Rule Created ESCU actions · hunting P O365 Email Suspicious Behavior Alert ESCU actions · alerting P O365 Email Transport Rule Changed ESCU actions · hunting P O365 Mailbox Email Forwarding Enabled ESCU actions · alerting P O365 New Email Forwarding Rule Created ESCU actions · alerting P O365 New Email Forwarding Rule Enabled ESCU actions · alerting P O365 Suspicious Admin Email Forwarding ESCU actions · hunting P O365 Suspicious User Email Forwarding ESCU actions · hunting P [LLM] Post-compromise malicious inbox rule for defense evasion (UAT-11764 / ARToken BEC) Bespoke actions · hunting DSDD [LLM] ARToken BEC toolkit: inbox forwarding/hiding rule creation on compromised M365 mailbox Bespoke actions · hunting DSΣ [LLM] Post-device-code malicious inbox rule creation (BEC prep) Bespoke actions · alerting DSP [LLM] Outbound email BCC'd to giftshop.club exfil domain (postmark-mcp backdoor) Bespoke actions · alerting DSΣPDD

Articles citing this technique (4)