Skip to content

DET0814 Detection of Email Addresses

Item Value
ID DET0814
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T1589.002 (Email Addresses)

Analytics

PRE

AN1946

Monitor for suspicious network traffic that could be indicative of probing for email addresses and/or usernames, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.

Log Sources
Data Component Name Channel
Network Traffic Content (DC0085) Network Traffic None
Mutable Elements
Field Description