Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0048 — Detect Remote Email Collection via Abnormal Login and Programmatic Access
DET0048

Detect Remote Email Collection via Abnormal Login and Programmatic Access

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0131 Analytic 0131
Windows

Detects adversaries accessing remote mail systems (e.g., Exchange Online, O365) using stolen credentials or OAuth tokens, followed by scripted access to mailbox contents via PowerShell, AADInternals, or unattended API queries. Detection focuses on abnormal logon sessions, user agents, IP locations, and scripted or tool-based email data access.

azure:signinlogs Abnormal sign-in from scripting tools (PowerShell, AADInternals) m365:purview MailItemsAccessed & Exchange Audit WinEventLog:PowerShell EventCode=4103, 4104, 4105, 4106 WinEventLog:Sysmon EventCode=3, 22
[UserAgentPattern] Filters user agents like 'PowerShell', 'AADInternals', 'python-requests' which can vary depending on script/tool.
[TimeWindow] Defines the temporal correlation window between login, command execution, and outbound email access.
[KnownIPLocations] Defines baseline geo/IP address ranges to suppress known corporate access.
[PrivilegedUserList] Defines the accounts considered privileged (admin, execs) and worthy of tighter thresholds.
AN0132 Analytic 0132
Office Suite

Monitors programmatic access to user mailboxes in cloud-based email systems (e.g., O365, Exchange Online) using APIs or tokens. Focuses on OAuth misuse, suspicious MailItemsAccessed patterns, scripted keyword searches, and connections from untrusted agents or locations.

m365:purview MailItemsAccessed, Search-Mailbox events azure:signinlogs Suspicious login to cloud mailbox system m365:unified Search-Mailbox, Get-MessageTrace, eDiscovery requests
[MailAccessVolumeThreshold] Number of emails accessed within time window to flag anomaly.
[OAuthClientIDAllowList] Allows tuning based on known app registrations.
[KeywordSearchFrequency] Flag high volumes of message searches using suspicious patterns.
[LoginGeolocationVariance] Trigger when IP geolocation varies significantly from user's historical profile.

Detected Techniques

1

Details

MITRE ID
DET0048
STIX ID
x-mitre-detection-strategy--00a515dc-e3be-4349-9c61-65a5c0ce815d
Analytics
2
Techniques Detected
1
By Tactic
Collection
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.