Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0814 — Detection of Email Addresses
DET0814

Detection of Email Addresses

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1946 Analytic 1946
PRE

Monitor for suspicious network traffic that could be indicative of probing for email addresses and/or usernames, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.

Network Traffic None

Detected Techniques

1

Reconnaissance (1)

Details

MITRE ID
DET0814
STIX ID
x-mitre-detection-strategy--33040f26-43e3-4c1d-8557-02f306bb028f
Analytics
1
Techniques Detected
1
By Tactic
Reconnaissance
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.