T1114 Email Collection — Detection & Response
Adversaries may target user email to collect sensitive information. Email data can reveal business strategies, credentials, intellectual property, and information about key personnel. Attackers target email through client-side access, remote access via web protocols, or covert forwarding rules that silently copy messages to an external mailbox.
Coverage at a glance
- Detections shipped
- 5
- Avg. verdict time
- < 5 min
- Data sources
- 4+
Threat context
How adversaries use T1114 Email Collection — Detection & Response
Adversaries may target user email to collect sensitive information. Email data can reveal business strategies, credentials, intellectual property, and information about key personnel. Attackers target email through client-side access, remote access via web protocols, or covert forwarding rules that silently copy messages to an external mailbox.
Business email compromise (BEC) and espionage campaigns frequently establish email forwarding rules as a persistence mechanism. Once an adversary has compromised an account, they create an Inbox rule to forward all or filtered messages to an external address, maintaining access to email content even after the primary compromise is remediated. This technique is particularly difficult to detect because forwarding rules look legitimate in isolation — the anomaly is their unexpected existence and external destination.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| New External Email Forwarding Rule Created A mailbox rule is created that forwards emails to an external, non-corporate email address. | High | Microsoft 365 / Google Workspace |
| Email Forwarding to Free Consumer Service Forwarding rule destination matches a free email provider (gmail.com, yahoo.com, proton.me) rather than a corporate domain. | Critical | Microsoft 365 Unified Audit |
| Bulk Email Export via Graph API A service principal or user account uses the Microsoft Graph API to read more than 500 emails in a 15-minute window. | High | Microsoft 365 Unified Audit |
| Transport Rule Added for External Forwarding A new Exchange transport rule is created that redirects emails matching certain criteria to an external domain. | Critical | Exchange Admin Audit |
| IMAP Access from New IP to Legacy Protocol IMAP or POP3 access to a mailbox from a new IP address — legacy protocols bypass MFA and are commonly used for email harvesting. | Medium | Microsoft 365 Sign-in Logs |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1114 Email Collection — Detection & Response: frequently asked questions
How common is the email forwarding rule technique?
Extremely common. It appears in the majority of BEC investigations and is a standard post-compromise persistence mechanism in nation-state espionage campaigns. CISA and FBI have issued multiple advisories specifically about this technique.
Can ManySignal detect forwarding rules created before it was deployed?
ManySignal can audit existing mailbox forwarding rules via the Microsoft 365 or Google Workspace APIs on initial setup. Any rules to external domains are surfaced in the investigation timeline.
What is T1114.003 specifically?
T1114.003 is the sub-technique for email forwarding rules specifically — automating email collection by creating Inbox rules that redirect messages to a controlled mailbox rather than manually accessing email. ManySignal has dedicated detections for this sub-technique.
Does ManySignal detect email collection through Outlook desktop client?
Local email collection (T1114.001) via Outlook PST export or MAPI access requires endpoint telemetry. If a CrowdStrike or SentinelOne connector is active, process-level file access to PST files is captured and correlated.
How does ManySignal differentiate legitimate forwarding from malicious?
ManySignal considers: destination domain (internal vs. external), creation context (is the creating account in an active session following suspicious events?), rule scope (all mail vs. filtered keywords), and timing (off-hours, post-authentication anomaly).
Can I get alerted on existing rules, not just new ones?
Yes. Configure a daily or weekly audit of all forwarding rules in your Microsoft 365 or Google Workspace tenant. ManySignal surfaces rules to non-corporate domains as low-severity informational alerts for review.
Does this detection work for on-premises Exchange?
Yes, but it requires forwarding Exchange Admin Audit logs to ManySignal via the syslog connector or a log forwarder. Exchange Online is monitored via the Microsoft 365 connector natively.
What MITRE mitigations are most effective against T1114?
M1041 (Encrypt Sensitive Information) makes email less useful even if collected. M1047 (Audit) — regular mailbox rule audits — is the primary detective control. M1032 (Multi-Factor Authentication) reduces initial compromise that enables rule creation.
Can ManySignal detect silent carbon copies (BCC rules)?
Yes. Exchange transport rules using BCC actions appear in Admin Audit logs. Mailbox BCC forwarding rules appear in MailboxAuditLog. Both are ingested by ManySignal.
How long after compromise is the forwarding rule typically created?
In most BEC investigations, forwarding rules are created within the first 15 minutes of initial account access. ManySignal's correlated timeline correlates the authentication anomaly with the subsequent rule creation for rapid detection.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.