Basyrix SOC Response Atlas by Basyrix

Collection

T1114 — Email Collection

Adversaries may target a mailbox to collect sensitive information — via mailbox forwarding rules, delegate access, or direct API/IMAP access — often after an initial account compromise, to support further targeting or data theft.

Any new mailbox forwarding rule, delegate grant, or bulk mailbox export activity following a suspicious sign-in should be treated as likely post-compromise collection, particularly when forwarding targets an external or unfamiliar address.

Platforms

Office 365, SaaS

Priority / status

medium / complete

Evidence to collect

  • Mailbox owner
  • Rule/delegate configuration details
  • Forwarding/redirect destination address
  • Creation timestamp and initiating identity
  • Volume of mail affected