Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1114

T1114Email Collection

T1114 — Email Collection is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 5 detection use cases covering it and 3 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
5Use cases
3Articles
3Sub-techniques
1Tactic

Sub-techniques (3)

Use cases covering this technique (5)

O365 New Forwarding Mailflow Rule Created ESCU actions · alerting P O365 PST export alert ESCU actions · alerting P [LLM] Malicious postmark-mcp BCC email exfiltration to phan@giftshop[.]club Bespoke actions · alerting DSP [LLM] Post-device-code token abuse: mailbox / OneDrive / Teams access from a new IP after device-code sign-in Bespoke actions · alerting DS [LLM] Malicious 'postmark-mcp' MCP server package present/executing on developer endpoints Bespoke delivery · alerting DSΣPDDCS

Articles citing this technique (3)