{
  "node_id": "mitre-attack-t1114-002-remote-email-collection",
  "title": "MITRE ATT&CK T1114.002: Remote Email Collection (Enterprise Tactic TA0009 - Collection)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1114.002 (Remote Email Collection) is an Enterprise Collection sub-technique of T1114 (Email Collection). Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange server to acquire information from within a network. Adversaries may also access externally facing Exchange services, Office 365, or Google Workspace to access email using credentials or access tokens. Tools such as MailSniper can be used to automate searches for specific keywords. Affected platforms: Windows, Office Suite. MITRE-documented mitigations include M1060 Out-of-Band Communications Channel, M1041 Encrypt Sensitive Information, M1032 Multi-factor Authentication. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-04, AC-16, AC-17, AC-19, AC-20, CM-02, CM-06.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-t1114-email-collection"
  ],
  "primary_citations_count": 7
}