Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1564.008

T1564.008Email Hiding Rules

T1564.008 — Email Hiding Rules is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 6 detection use cases covering it and 3 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
6Use cases
3Articles
0Sub-techniques
1Tactic

Use cases covering this technique (6)

O365 BEC Email Hiding Rule Created ESCU actions · alerting P O365 Email New Inbox Rule Created ESCU actions · hunting P O365 Email Transport Rule Changed ESCU actions · hunting P [LLM] Post-compromise malicious inbox rule for defense evasion (UAT-11764 / ARToken BEC) Bespoke actions · hunting DSDD [LLM] ARToken BEC toolkit: inbox forwarding/hiding rule creation on compromised M365 mailbox Bespoke actions · hunting DSΣ [LLM] Post-device-code malicious inbox rule creation (BEC prep) Bespoke actions · alerting DSP

Articles citing this technique (3)