kevmap

TechniquesT1114.002 › AN0132

AN0132 Analytic 0132

Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Monitors programmatic access to user mailboxes in cloud-based email systems (e.g., O365, Exchange Online) using APIs or tokens. Focuses on OAuth misuse, suspicious MailItemsAccessed patterns, scripted keyword searches, and connections from untrusted agents or locations.</p>
Detects
T1114.002 Remote Email Collection
Part of
DET0048 Detect Remote Email Collection via Abnormal Login and Programmatic Access

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:purviewMailItemsAccessed, Search-Mailbox eventsDC0038 Application Log Content
azure:signinlogsSuspicious login to cloud mailbox systemDC0067 Logon Session Creation
m365:unifiedSearch-Mailbox, Get-MessageTrace, eDiscovery requestsDC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MailAccessVolumeThresholdNumber of emails accessed within time window to flag anomaly.
OAuthClientIDAllowListAllows tuning based on known app registrations.
KeywordSearchFrequencyFlag high volumes of message searches using suspicious patterns.
LoginGeolocationVarianceTrigger when IP geolocation varies significantly from user's historical profile.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2012-0767Adobe Flash PlayerMapped