Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as [MailSniper](https://attack.mitre.org/software/S0413) can be used to automate searches for specific keywords.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Out-of-Band Communications Channel
is blocked by Encrypt Sensitive Information
is blocked by Multi-factor Authentication
is blocked by Detect Remote Email Collection via Abnormal Login and Programmatic Access
is blocked by Secure Baseline Configurations
is blocked by Continuous Monitoring
is blocked by Cybersecurity & Data Protection Attributes
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Media & Data Retention
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Identification & Authentication for Organizational Users
is blocked by Authenticator Management
is blocked by Access Enforcement
is blocked by Access Control For Mobile Devices
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Out-of-Band Channels
is blocked by Remote Access
Impressum Deutsch Englisch