Email Collection: Remote Email Collection

Threat Actors may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Threat Actors may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Threat Actors may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords.

ID: ATAGS-T1179.002
Sub-technique of:  ATAGS-T1179
Tactic: Collection
Targeted Components: Software
Responsibility: Shared
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.