// MITRE ATT&CK

T1684.002 · Email Spoofing

🎯 Stealth LinuxmacOSOffice SuiteWindows Sub-technique

Sub-technique of T1684 · Social Engineering.

Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses.(Citation: Proofpoint TA427 April 2024) In addition to actual email content, email headers (such as the FROM header, which contains...

How to detect & mitigate it

Detecting Email Spoofing starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.