LoFP
/
t1114
t1114
Title
Tags
administrators and users sometimes prefer backing up their email data by moving the email files into a different folder. these attempts will be detected by the search.
t1114
t1114.001
endpoint
splunk
administrators may create custom email routes in google workspace based on organizational policies, administrative preference or for security purposes regarding spam.
t1114
google_workspace
elastic
administrators might temporarily share a mailbox with all users for legitimate reasons, such as troubleshooting, migrations, or other administrative tasks. some organizations use shared mailboxes for teams or departments where multiple users need access to the same mailbox. filter as needed.
t1114
T1114.002
o365 tenant
splunk
compliance content searche exports may be executed for legitimate purposes, filter as needed.
t1114
T1114.002
o365 tenant
splunk
compliance content searches may be executed for legitimate purposes, filter as needed.
t1114
T1114.002
o365 tenant
splunk
email forwarding may be configured for legitimate purposes, filter as needed.
t1114
T1114.003
o365 tenant
splunk
exporting a pst can be done for legitimate purposes by legitimate sources, but due to the sensitive nature of pst content, it must be monitored.
t1114
m365
sigma
forwarding mail flow rules may be created for legitimate reasons, filter as needed.
t1114
o365 tenant
splunk
go utilities that use staaldraad awesome ntlm library
t1059
t1087
t1114
t1550
t1550.002
windows
sigma
legitamate access by security administators for incident response measures.
t1114
T1114.002
t1567
o365 tenant
splunk
legitimate exchange system administration activity.
t1005
t1059
t1098
t1114
windows
elastic
pst export can be done for legitimate purposes but due to the sensitive nature of its content it must be monitored.
t1114
o365 tenant
splunk
the false-positive rate will vary based on how you set the deviation_threshold and data_samples values. our recommendation is to adjust these values based on your network traffic to and from your email servers.
t1114
T1114.002
endpoint
splunk
there are legitimate scenarios in wich an application registrations requires mailbox read access. filter as needed.
t1098
t1098.003
t1114
T1114.002
o365 tenant
splunk
users and administrators can create inbox rules for legitimate purposes. verify if it complies with the company policy and done with the user's consent. exceptions can be added to this rule to filter expected behavior.
t1114
o365
elastic
users emailing for legitimate business purposes that appear suspicious.
t1114
T1114.003
o365 tenant
splunk
users may create email forwarding rules for legitimate purposes. filter as needed.
t1114
T1114.003
o365 tenant
splunk
while there are legitimate scenarios for these permissions, such as an executive assistant needing access to an executive's mailbox, there are also malicious scenarios. investigate and filter as needed.
t1098
T1098.002
t1114
T1114.002
o365 tenant
splunk