Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0355 — Detection Strategy for Email Bombing
DET0355

Detection Strategy for Email Bombing

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN1008 Analytic 1008
Windows

Detect abnormally high volume of inbound email messages or repetitive attachments being delivered to a single mailbox within a short time window. Defenders should look for anomalous spikes in message counts and repetitive attachment file creation events correlated with targeted users.

m365:unified Send/Receive: Unusual spikes in inbound messages to a single recipient WinEventLog:Sysmon EventCode=11
[TimeWindow] Defines the aggregation interval (e.g., 5 minutes, 1 hour) for detecting spikes in inbound email traffic.
[RecipientThreshold] Defines maximum number of acceptable messages per user before triggering anomaly.
[AttachmentSizeThreshold] Defines the size threshold for repetitive attachments to be flagged.
AN1009 Analytic 1009
Linux

Monitor mail server logs (e.g., Postfix, Sendmail) for excessive connections or inbound message counts targeting a single recipient. Correlate with repetitive attachment storage in /var/mail or /var/spool/mail directories.

auditd:SYSCALL File creation events in /var/mail or /var/spool/mail exceeding baseline thresholds Application:Mail High-frequency inbound mail activity to a specific recipient address
[MailVolumeThreshold] Tunable value for the maximum acceptable emails per minute per user.
[AttachmentPatternList] List of suspicious attachment extensions that may be abused for repetitive delivery.
AN1010 Analytic 1010
Office Suite

Detect abnormal use of email clients (e.g., Outlook, Thunderbird) showing mass arrival of messages or repetitive attachments being locally stored. Correlate message volume with file creation activity in mail cache directories.

m365:exchange MailDelivery: High-frequency delivery of messages or attachments to a single recipient
[UserContext] Context for distinguishing between VIP or sensitive recipients and general users.
AN1011 Analytic 1011
macOS

Monitor unified logs and Mail.app activity for repetitive incoming messages with attachments. Defenders should look for large volumes of incoming mail stored under ~/Library/Mail with unusual timing or repetitive subjects.

macos:unifiedlog Repetitive inbound email delivery activity logged within a short time window fs:fsusage create: Attachment file creation in ~/Library/Mail directories
[FileCountThreshold] Threshold for repetitive attachment files created within a defined interval.

Detected Techniques

1

Details

MITRE ID
DET0355
STIX ID
x-mitre-detection-strategy--9a66295a-9f47-47a8-bda4-935cd311186a
Analytics
4
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.