Log sources › Application:Mail
Application:Mail
Inverted view: what can be detected if this is the log you have. Linux
6
channels
6
analytics
6
techniques
18
KEV CVEs reachable
"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.
Channels
| Channel | Data components | Analytics | Techniques |
|---|---|---|---|
High-frequency inbound mail activity to a specific recipient address |
DC0038 Application Log Content | AN1009 | 1 |
Inbound email attachments logged from MTAs with suspicious metadata |
DC0038 Application Log Content | AN0656 | 1 |
Inbound emails containing hyperlinks from suspicious sources |
DC0038 Application Log Content | AN0299 | 1 |
Inbound messages with anomalous headers, spoofed SPF/DKIM failures |
DC0038 Application Log Content | AN0189 | 1 |
Mismatch between authenticated username and From header in email |
DC0038 Application Log Content | AN0793 | 1 |
smtpd$.*$: .*from=[.*@internaldomain.com](mailto:.*@internaldomain.com) to=[.*@internaldomain.com](mailto:.*@internaldomain.com) |
DC0038 Application Log Content | AN0148 | 1 |
Techniques detectable from this source
| Technique | Tactics | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1534 Internal Spearphishing | lateral movement | 0 | 0 |
| T1566 Phishing | initial access | 14 | 6 |
| T1566.001 Spearphishing Attachment | initial access | 24 | 7 |
| T1566.002 Spearphishing Link | initial access | 4 | 5 |
| T1667 Email Bombing | impact | 0 | 0 |
| T1684.001 Impersonation | stealth | 0 | 0 |
KEV CVEs reachable from this source
| CVE | Vendor / product | Via technique | State |
|---|---|---|---|
| CVE-2013-0640 | Adobe Reader and Acrobat | T1566.001 | Mapped |
| CVE-2015-5119 | Adobe Flash Player | T1566.002 | Mapped |
| CVE-2017-11292 | Adobe Flash Player | T1566.001 | Mapped |
| CVE-2017-11882 | Microsoft Office | T1566.001 | Mapped |
| CVE-2021-40449 | Microsoft Windows | T1566 | Mapped |
| CVE-2022-34713 | Microsoft Windows | T1566 | Mapped |
| CVE-2022-41033 | Microsoft Windows COM+ Event System Service | T1566.001 | Mapped |
| CVE-2022-41128 | Microsoft Windows | T1566 | Mapped |
| CVE-2023-2533 | PaperCut NG/MF | T1566.002 | Mapped |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | T1566.001 | Mapped |
| CVE-2023-36884 | Microsoft Windows | T1566 | Stale |
| CVE-2024-11182 | MDaemon Email Server | T1566 | Mapped |
| CVE-2024-21413 | Microsoft Office Outlook | T1566.002 | Mapped |
| CVE-2024-27443 | Synacor Zimbra Collaboration Suite (ZCS) | T1566.002 | Mapped |
| CVE-2024-42009 | Roundcube Webmail | T1566.002 | Mapped |
| CVE-2025-0411 | 7-Zip 7-Zip | T1566.001 | Mapped |
| CVE-2025-24054 | Microsoft Windows | T1566 | Mapped |
| CVE-2025-33053 | Microsoft Windows | T1566.001 | Mapped |