kevmap

Log sources › m365:messagetrace

m365:messagetrace

Inverted view: what can be detected if this is the log you have. Office Suite, Windows

5
channels
5
analytics
5
techniques
0
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
AuthenticationDetails=fail OR SPF=fail OR DKIM=fail OR DMARC=fail DC0038 Application Log Content AN1202 1
Inbound email matches crafted rule trigger pattern tied to persistence logic DC0064 Command Execution AN0264 1
Inbound email triggering Outlook to auto-access folder tied to malicious Home Page DC0064 Command Execution AN0503 1
Inbound email triggers execution of mailbox-stored custom form DC0064 Command Execution AN0086 1
X-MS-Exchange-Organization-AutoForwarded DC0038 Application Log Content AN1591 1

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1114.003 Email Forwarding Rulecollection60
T1137.003 Outlook Formspersistence10
T1137.004 Outlook Home Pagepersistence00
T1137.005 Outlook Rulespersistence00
T1684.002 Email Spoofingstealth00