kevmap

TechniquesT1684.002 › AN1205

AN1205 Analytic 1205

Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Correlates Office 365 or Google Workspace audit logs for spoofed sender addresses, failed email authentication, and anomalies in message delivery metadata. Defender observes failed SPF/DKIM checks and domain mismatches tied to suspicious campaigns.</p>
Detects
T1684.002 Email Spoofing
Part of
DET0431 Detection Strategy for Email Spoofing

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
saas:emailAuthenticationFailures (SPF/DKIM/DMARC) OR Domain MismatchDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MessageVolumeThresholdDefines thresholds for spoofed messages volume before alerts trigger, reducing noise for isolated misconfigs.
TargetedUserGroupsRestricts higher-sensitivity detection to high-value groups (executives, admins, finance) for efficiency.