kevmap

TechniquesT1684 › AN2033

AN2033 Analytic 2033

Office Suite · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects suspicious inbound communications or collaboration requests followed by rapid sensitive user actions such as file sharing changes, macro enablement, OAuth consent, credential submission, or financial workflow approvals that deviate from historical relationships or normal approval patterns.</p>
Detects
T1684 Social Engineering
Part of
DET0899 Detect Social Engineering

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:unifiedMailItemsAccessed; AddedInboxRule; ConsentToApplication; SharingSetDC0038 Application Log Content
m365:exchangeExternal sender message followed by user action involving links or attachmentsDC0038 Application Log Content
m365:teamsExternal chat request or new tenant communication preceding approval activityDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ActionAfterMessageWindowTime window between inbound communication and sensitive action
TrustedDomainAllowlistKnown legitimate vendors or partner domains
ApprovalAmountThresholdMonetary threshold for finance workflows