Umbra Wiki technique technique/T1114.002
Back to wiki

T1114.002 — Remote Email Collection

provenance: imported · ATT&CK: T1114.002

T1114.002: Remote Email Collection

MITRE ATT&CK® Enterprise technique

Tactics Collection
Platforms Office Suite, Windows
Permissions required
Version 1.3
Parent technique T1114

Description

Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1114/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/