Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0047 — Detect Local Email Collection via Outlook Data File Access and Command Line Tooling
DET0047

Detect Local Email Collection via Outlook Data File Access and Command Line Tooling

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0130 Analytic 0130
Windows

Detection focuses on processes that attempt to locate, access, or exfiltrate local Outlook data files (.pst/.ost) using file system access, native Windows utilities (e.g., PowerShell, WMI), or remote access tools with file browsing capabilities. The behavior chain includes directory enumeration, file access, optional compression or staging, and network transfer.

WinEventLog:Security EventCode=4663, 4670, 4656 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=3, 22
[TargetFilePathPattern] Regex or wildcard patterns for sensitive Outlook file paths (.ost/.pst) depending on organizational deployment.
[TimeWindow] Timeframe used to correlate related file access, process creation, and exfiltration events.
[UserContext] Limit detection to user accounts not normally interacting with Outlook file locations (e.g., service accounts, low-privileged users).
[ProcessAllowList] Filter known legitimate Outlook-accessing processes to reduce false positives.

Detected Techniques

1

Details

MITRE ID
DET0047
STIX ID
x-mitre-detection-strategy--8fb1967e-478f-4a83-9fb9-3da1015b8a26
Analytics
1
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.