{"id":"T1087.003","name":"Email Account","url":"https://attack.mitre.org/techniques/T1087/003","tactics":["discovery"],"platforms":["Windows","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0229","stix_id":"x-mitre-detection-strategy--e2f961bd-ddc5-4940-bc62-e2b0bd3405f8","name":"Enumeration of Global Address Lists via Email Account Discovery","url":"https://attack.mitre.org/detectionstrategies/DET0229","analytics":[{"id":"AN0641","stix_id":"x-mitre-analytic--cd91348f-296f-4007-a853-6d06d8175210","name":"Analytic 0641","description":"Enumeration of global address lists or email account metadata via PowerShell cmdlets (e.g., Get-GlobalAddressList) or MAPI/RPC from non-admin, non-mailserver systems.","url":"https://attack.mitre.org/detectionstrategies/DET0229#AN0641","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CommandLinePattern","description":"Match variations of Get-GlobalAddressList, Get-Recipient, and related cmdlets."},{"field":"HostRole","description":"Suppress expected usage on Exchange servers or known IT admin consoles."},{"field":"TimeWindow","description":"Detect bulk execution patterns in short intervals, often used during recon."}],"live":true,"detection_strategies":["DET0229"],"techniques":["T1087.003"]},{"id":"AN0642","stix_id":"x-mitre-analytic--e0ad2e3d-c109-4af0-ac44-0d4cd45407c2","name":"Analytic 0642","description":"Suspicious querying of organization-wide directory data via Google Workspace Directory API or Outlook GAL sync in high volume from abnormal users, service accounts, or unknown device contexts.","url":"https://attack.mitre.org/detectionstrategies/DET0229#AN0642","platforms":["Office Suite"],"log_source_references":[{"name":"gcp:audit","channel":"Directory API Access: users.list or groups.list","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"gcp-audit"},{"name":"m365:unified","channel":"GAL Lookup or Address Book download","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"azure:signinlogs","channel":"Unusual Token Usage or Application Consent","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"APIQueryVolume","description":"Set thresholds for excessive use of 'users.list' or recursive group enumerations."},{"field":"UserContext","description":"Flag non-admin or previously unseen user agents requesting directory information."},{"field":"AppSource","description":"Distinguish between sanctioned sync tools and unauthorized scripts or OAuth tokens."}],"live":true,"detection_strategies":["DET0229"],"techniques":["T1087.003"]}],"live":true,"version":"1.0","techniques":["T1087.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}