M ManySignal
T1114 MITRE ATT&CK

T1114 Email Collection — Detection & Response

Adversaries may target user email to collect sensitive information. Email data can reveal business strategies, credentials, intellectual property, and information about key personnel. Attackers target email through client-side access, remote access via web protocols, or covert forwarding rules that silently copy messages to an external mailbox.

Coverage at a glance

Detections shipped
5
Avg. verdict time
< 5 min
Data sources
4+

Threat context

How adversaries use T1114 Email Collection — Detection & Response

Adversaries may target user email to collect sensitive information. Email data can reveal business strategies, credentials, intellectual property, and information about key personnel. Attackers target email through client-side access, remote access via web protocols, or covert forwarding rules that silently copy messages to an external mailbox.

Business email compromise (BEC) and espionage campaigns frequently establish email forwarding rules as a persistence mechanism. Once an adversary has compromised an account, they create an Inbox rule to forward all or filtered messages to an external address, maintaining access to email content even after the primary compromise is remediated. This technique is particularly difficult to detect because forwarding rules look legitimate in isolation — the anomaly is their unexpected existence and external destination.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

New External Email Forwarding Rule Created

A mailbox rule is created that forwards emails to an external, non-corporate email address.

High Microsoft 365 / Google Workspace

Email Forwarding to Free Consumer Service

Forwarding rule destination matches a free email provider (gmail.com, yahoo.com, proton.me) rather than a corporate domain.

Critical Microsoft 365 Unified Audit

Bulk Email Export via Graph API

A service principal or user account uses the Microsoft Graph API to read more than 500 emails in a 15-minute window.

High Microsoft 365 Unified Audit

Transport Rule Added for External Forwarding

A new Exchange transport rule is created that redirects emails matching certain criteria to an external domain.

Critical Exchange Admin Audit

IMAP Access from New IP to Legacy Protocol

IMAP or POP3 access to a mailbox from a new IP address — legacy protocols bypass MFA and are commonly used for email harvesting.

Medium Microsoft 365 Sign-in Logs

T1114 Email Collection — Detection & Response: frequently asked questions

How common is the email forwarding rule technique?

Extremely common. It appears in the majority of BEC investigations and is a standard post-compromise persistence mechanism in nation-state espionage campaigns. CISA and FBI have issued multiple advisories specifically about this technique.

Can ManySignal detect forwarding rules created before it was deployed?

ManySignal can audit existing mailbox forwarding rules via the Microsoft 365 or Google Workspace APIs on initial setup. Any rules to external domains are surfaced in the investigation timeline.

What is T1114.003 specifically?

T1114.003 is the sub-technique for email forwarding rules specifically — automating email collection by creating Inbox rules that redirect messages to a controlled mailbox rather than manually accessing email. ManySignal has dedicated detections for this sub-technique.

Does ManySignal detect email collection through Outlook desktop client?

Local email collection (T1114.001) via Outlook PST export or MAPI access requires endpoint telemetry. If a CrowdStrike or SentinelOne connector is active, process-level file access to PST files is captured and correlated.

How does ManySignal differentiate legitimate forwarding from malicious?

ManySignal considers: destination domain (internal vs. external), creation context (is the creating account in an active session following suspicious events?), rule scope (all mail vs. filtered keywords), and timing (off-hours, post-authentication anomaly).

Can I get alerted on existing rules, not just new ones?

Yes. Configure a daily or weekly audit of all forwarding rules in your Microsoft 365 or Google Workspace tenant. ManySignal surfaces rules to non-corporate domains as low-severity informational alerts for review.

Does this detection work for on-premises Exchange?

Yes, but it requires forwarding Exchange Admin Audit logs to ManySignal via the syslog connector or a log forwarder. Exchange Online is monitored via the Microsoft 365 connector natively.

What MITRE mitigations are most effective against T1114?

M1041 (Encrypt Sensitive Information) makes email less useful even if collected. M1047 (Audit) — regular mailbox rule audits — is the primary detective control. M1032 (Multi-Factor Authentication) reduces initial compromise that enables rule creation.

Can ManySignal detect silent carbon copies (BCC rules)?

Yes. Exchange transport rules using BCC actions appear in Admin Audit logs. Mailbox BCC forwarding rules appear in MailboxAuditLog. Both are ingested by ManySignal.

How long after compromise is the forwarding rule typically created?

In most BEC investigations, forwarding rules are created within the first 15 minutes of initial account access. ManySignal's correlated timeline correlates the authentication anomaly with the subsequent rule creation for rapid detection.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.