kevmap

Log sources › Application:Mail

Application:Mail

Inverted view: what can be detected if this is the log you have. Linux

6
channels
6
analytics
6
techniques
18
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
High-frequency inbound mail activity to a specific recipient address DC0038 Application Log Content AN1009 1
Inbound email attachments logged from MTAs with suspicious metadata DC0038 Application Log Content AN0656 1
Inbound emails containing hyperlinks from suspicious sources DC0038 Application Log Content AN0299 1
Inbound messages with anomalous headers, spoofed SPF/DKIM failures DC0038 Application Log Content AN0189 1
Mismatch between authenticated username and From header in email DC0038 Application Log Content AN0793 1
smtpd$.*$: .*from=[.*@internaldomain.com](mailto:.*@internaldomain.com) to=[.*@internaldomain.com](mailto:.*@internaldomain.com) DC0038 Application Log Content AN0148 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1534 Internal Spearphishinglateral movement00
T1566 Phishinginitial access146
T1566.001 Spearphishing Attachmentinitial access247
T1566.002 Spearphishing Linkinitial access45
T1667 Email Bombingimpact00
T1684.001 Impersonationstealth00

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2013-0640Adobe Reader and Acrobat T1566.001 Mapped
CVE-2015-5119Adobe Flash Player T1566.002 Mapped
CVE-2017-11292Adobe Flash Player T1566.001 Mapped
CVE-2017-11882Microsoft Office T1566.001 Mapped
CVE-2021-40449Microsoft Windows T1566 Mapped
CVE-2022-34713Microsoft Windows T1566 Mapped
CVE-2022-41033Microsoft Windows COM+ Event System Service T1566.001 Mapped
CVE-2022-41128Microsoft Windows T1566 Mapped
CVE-2023-2533PaperCut NG/MF T1566.002 Mapped
CVE-2023-2868Barracuda Networks Email Security Gateway (ESG) Appliance T1566.001 Mapped
CVE-2023-36884Microsoft Windows T1566 Stale
CVE-2024-11182MDaemon Email Server T1566 Mapped
CVE-2024-21413Microsoft Office Outlook T1566.002 Mapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS) T1566.002 Mapped
CVE-2024-42009Roundcube Webmail T1566.002 Mapped
CVE-2025-04117-Zip 7-Zip T1566.001 Mapped
CVE-2025-24054Microsoft Windows T1566 Mapped
CVE-2025-33053Microsoft Windows T1566.001 Mapped