detections
- ID: DT041
- Created: 01st June 2024
- Updated: 01st June 2024
- Contributor: The ITM Team
Email Gateway
Email gateway solutions offer the ability to trace inbound and outbound emails to an organization. This can be used to retrieve information such as emails sent or received, the subject line, content, attachments, timestamps, and recipients.
Sections
| ID | Name | Description |
|---|---|---|
| IF010 | Exfiltration via Email | A subject uses electronic mail to exfiltrate data. This can be achieved through including data in the email subject line or body, or utilizing email attachments to send files. |
| PR022 | Social Engineering (Outbound) | A subject deceptively manipulates and/or persuades others in order to gain access to devices, systems or services that hold sensitive information, or to otherwise cause harm or undermine a target organization. |
| MT020 | Ideology | A subject is motivated by ideology to access, destroy, or exfiltrate data, or otherwise violate internal policies in pursuit of their ideological goals.
Ideology is a structured system of ideas, values, and beliefs that shapes an individual’s understanding of the world and informs their actions. It often encompasses political, economic, and social perspectives, providing a comprehensive and sometimes rigid framework for interpreting events and guiding decision-making.
Individuals driven by ideology often perceive their actions as morally justified within the context of their belief system. Unlike those motivated by personal grievances or personal gain, ideological insiders act in service of a cause they deem greater than themselves. |
| IF041 | Unauthorized Organizational Representation | A subject falsely or improperly represents that they possess authority to speak, decide, approve, negotiate, instruct, certify, or make commitments on behalf of the organization. The subject uses their genuine association with the organization, their role, access to internal communication channels, or knowledge of organizational processes to make the representation appear legitimate.
Unauthorized Organizational Representation may occur through email, collaboration platforms, telephone calls, meetings, social media, customer communications, supplier negotiations, contractual discussions, regulatory engagement, public statements, or internal directives. The subject may claim authority they do not hold, act outside the limits of delegated authority, or omit information that would make the lack of authorization apparent.
The behavior may result in unauthorized commitments, misleading statements, improper instructions, reputational harm, financial liability, disclosure of protected information, disruption of established decision-making, or reliance by an internal or external party. A representation may be harmful even where the subject does not obtain access or impersonate another named individual.
This object differs from PR027 – Impersonation. Impersonation concerns adopting, fabricating, or misrepresenting identity to enable access or another planned action. Unauthorized Organizational Representation concerns misuse of actual or apparent institutional authority. Both objects may apply where the subject assumes another person’s identity and then issues instructions or commitments on behalf of the organization.
Investigators should examine delegated-authority records, approval requirements, communication history, signature blocks, meeting records, contractual limits, and whether recipients reasonably relied upon the representation. |
| PR050 | Trusted Relationship Cultivation | A subject deliberately develops a relationship of trust with a colleague, administrator, service provider, customer, or control owner to obtain future assistance, information, approval, or reduced scrutiny.
The conduct may involve repeatedly offering help, volunteering for tasks, creating dependency, demonstrating apparent reliability, or establishing informal communication outside approved processes. The relationship is later used to secure exceptional access, accelerate a request, obtain confidential information, bypass verification, or discourage challenge.
This would not classify ordinary professional relationship-building. Investigative relevance arises where the relationship is developed or exploited to enable a subsequent infringement. |
| IF044 | Abuse of Decision-Making Authority | A subject deliberately uses a decision-making authority granted through their organizational role to approve, deny, waive, prioritize, suppress, or otherwise determine an outcome for an unauthorized purpose.
The subject may be technically and procedurally entitled to make the decision. The infringement arises because the authority is exercised contrary to the organization’s interests, applicable policy, delegated limits, or the legitimate purpose for which the authority was granted.
This behavior may be difficult to identify through conventional access-control monitoring because the subject acts through authorized workflows and assigned permissions. Investigation requires examination of the decision, its stated justification, the subject’s relationship to affected parties, applicable policy requirements, and comparable decisions made under similar circumstances.
This is narrower than general “authority abuse.” It focuses on the improper exercise of an entrusted decision right. |
| IF010.001 | Exfiltration via Corporate Email | A subject exfiltrates information using their corporate-issued mailbox, either via software or webmail. They will access the conversation at a later date to retrieve information on a different system. |
| IF010.002 | Exfiltration via Personal Email | A subject exfiltrates information using a mailbox they own or have access to, either via software or webmail. They will access the conversation at a later date to retrieve information on a different system. |
| PR015.003 | Email Forwarding Rule | The subject creates an email forwarding rule to transport any incoming emails from one mailbox to another. |
| MT012.002 | Non-Violent Threats and Intimidation | The subject acts under coercion stemming from threats that target reputation, professional standing, financial stability, or exposure of personal secrets. These threats may be digitally delivered. While these actions stop short of threatening physical harm, they can exert intense psychological pressure, particularly when the subject believes their career, relationships, or public image are at imminent risk.
This type of coercion may originate from:
Unlike ideological motivation or personal gain, this behavior is driven by fear of exposure or ruin, not alignment with the threat actor’s objectives. Subjects may act reluctantly, leave minimal technical traces of coordination, and revert to baseline behavior once the coercive force is removed. |
| MT012.001 | Social Engineering (Inbound) | A third party deceptively manipulates and/or persuades a subject to divulge information, or gain access to devices or systems, or to otherwise cause harm or undermine a target organization. |
| IF011.001 | Intentionally Weakening Network Security Controls For a Third Party | The subject intentionally weakens or bypasses network security controls for a third party, such as providing credentials or disabling security controls. |
| AF027.001 | Email Deletion | The subject deliberately deletes emails - either sent, received, or both - with the intent to obstruct investigative visibility, remove evidence of policy violations, or eliminate traces of communication relevant to an insider event. While routine inbox maintenance is common, patterns of targeted deletion may indicate purposeful concealment. |
| PR025.005 | File Download via Email | The subject retrieves files from email systems, typically via attachments or embedded download links within corporate or personal email accounts. This includes access through thick clients (e.g., Outlook) or webmail interfaces.
Email-based file retrieval is a common and low-friction method for introducing external content into the environment. Attachments may originate from external senders, personal accounts, or previously staged communications. |
| PR020.004 | Masquerading Sensitive Data as Personal Files | A subject intentionally alters the filename, file extension, metadata tags, document properties, or visible descriptive attributes of sensitive organizational data to make it appear to be benign personal information. This may include disguising proprietary, regulated, technical, financial, customer, or strategic material as photographs, household records, recipes, receipts, travel documents, music files, temporary files, or other low-risk personal content.
This technique is typically performed before data staging, transfer, or exfiltration. It may reduce scrutiny during manual review, mislead investigators during triage, or weaken controls that rely on filename, extension, path, metadata, or user-applied classification fields. Investigators should assess this behavior in proximity to file access, bulk download, archive creation, removable media use, cloud upload, email transmission, or other indicators of planned data loss.
A common scenario occurs during offboarding, where a subject is permitted to remove or transfer legitimate personal files from a corporate device before returning the asset. The subject may exploit this authorized window by disguising sensitive organizational data as personal material, relying on the expectation that files labeled as photographs, tax records, household documents, or other personal content will receive less scrutiny. This behavior can create ambiguity for investigators because the initial transfer context may appear procedurally authorized, while the concealed content indicates preparation for later exfiltration or unauthorized retention.
Examples of Use
|
| PR022.001 | Outbound Social Engineering via Email | A subject uses email to deceive, manipulate, or persuade another person into disclosing information, performing an action, approving a request, or enabling access that may support a later infringement. The subject may send messages from a corporate mailbox, personal account, spoofed address, compromised account, or third-party service in order to create a convincing pretext.
This behavior may involve impersonating a colleague, manager, vendor, customer, service provider, or trusted authority. The subject may use urgency, confidentiality, procedural familiarity, or organizational context to influence the recipient’s decision-making. The intended outcome may include obtaining credentials, internal process information, sensitive documents, access approvals, financial changes, or other information or actions that prepare the subject for further misuse. |
| PR022.002 | Outbound Social Engineering via Voice | A subject uses voice communication to deceive, pressure, or persuade another person into disclosing information, changing a control, approving access, or taking an action that may support a later infringement. This may occur through corporate telephony, mobile calls, voice over IP services, conference platforms, helpdesk calls, or external calling infrastructure.
This behavior may involve impersonation, false authority, urgency, familiarity, or procedural manipulation. The subject may contact service desk personnel, administrators, reception staff, colleagues, vendors, or other individuals who can influence access, identity verification, physical entry, operational processes, or administrative controls. The intended outcome may include account recovery, password reset assistance, disclosure of internal procedures, access approval, security exception handling, or other enabling action. |
| IF043.003 | Equipment or Facility Diversion | A subject redirects organizational equipment, vehicles, facilities, laboratories, production capability, or other physical assets toward an unauthorized use. Harm may include reduced availability, damage, operating cost, or disruption to legitimate activity. |
| IF044.001 | Unauthorized Approval | A subject uses delegated authority to approve a request, transaction, entitlement, exception, appointment, payment, access grant, or other organizational action without a legitimate basis.
Examples include:
The defining evidence is an affirmative decision made through authority legitimately assigned to the subject. |
| IF044.002 | Improper Denial | A subject uses organizational authority to deny another person a service, benefit, request, opportunity, access right, payment, review, or other outcome without a legitimate organizational basis.
Examples include:
|
| IF044.003 | Improper Preferential Treatment | A subject uses decision-making authority to provide an unauthorized advantage to a person, organization, account, supplier, applicant, or other beneficiary.
Examples include:
|
| IF044.004 | Suppression of Escalation or Review | A subject uses their authority to prevent, terminate, delay, redirect, or improperly narrow a required organizational review, escalation, complaint, referral, or investigation.
Examples include:
|
| IF044.005 | Unauthorized Waiver or Control Exception | A subject improperly waives, bypasses, suspends, or grants an exception to a mandatory organizational control using authority available through their role.
Examples include:
|
| IF044.006 | Unauthorized Prioritization or Deprioritization | A subject uses decision-making authority to improperly accelerate, delay, elevate, or deprioritize a request, case, transaction, task, customer, or other item within an organizational process.
Examples include:
|
| PR040.001 | Testing Data Transfer Controls | A subject conducts a limited transfer of non-sensitive or low-value data to determine whether organizational controls detect, block, quarantine, or escalate the activity.
The subject may send a file to a personal email account, upload content to an unapproved cloud storage service, transfer data through a messaging platform, or use another external destination before attempting a larger or more sensitive transfer. They may vary the file type, size, classification, destination, compression, encryption, or transfer method to identify which conditions trigger Data Loss Prevention (DLP), web proxy, email gateway, or cloud access security controls.
The behavior may include a pause after the test while the subject waits to determine whether security personnel, management, or another authority responds. A successful test may establish a viable exfiltration route or reveal thresholds that can be avoided during a later infringement. |