kevmap

TechniquesT1589.002 › AN1946

AN1946 Analytic 1946

PRE · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Monitor for suspicious network traffic that could be indicative of probing for email addresses and/or usernames, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.</p>
Detects
T1589.002 Email Addresses
Part of
DET0814 Detection of Email Addresses

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
Network TrafficNoneDC0085 Network Traffic Content