- How do SOC analysts detect Email Collection?
- Detection centers on SIEM, XDR telemetry for the collection phase of the attack. Monitor Exchange and Office 365 audit logs for unusual email export operations, mailbox access by non-owners, and use of Exchange Web Services for bulk email retrieval from accounts with no administrative function. Alert on email forwarding rule creation, particularly rules that forward messages to external email addresses or that use broad criteria to forward all messages or messages matching business-sensitive keywords.
- What does a Email Collection alert look like?
- A representative SIEM detection is "Email Forwarding Rule Created to External Account" (high severity): Office 365 audit log recorded creation of a new inbox rule for CFO account ceo@company.com that forwards all messages containing keywords "invoice", "payment", "wire transfer", and "bank" to an external Gmail address. This forwarding rule was created at 11:43 PM using the account after successful MFA bypass. The rule enables ongoing email monitoring and is a common precursor to BEC fraud.
- Which tools detect Email Collection, and how can I practice?
- Email Collection (T1114) is best surfaced with SIEM, XDR telemetry, which exposes the collection signals described above. Practice detecting it on those exact consoles in SOCSimulator Operations, free.