{
  "node_id": "mitre-attack-t1564-008-email-hiding-rules",
  "title": "MITRE ATT&CK T1564.008: Email Hiding Rules (Enterprise Tactic TA0005 - Defense Evasion)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1564.008 (Email Hiding Rules) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow users to create inbox rules for various email functions, including moving emails to other folders, marking emails as read, or deleting emails. Rules may be created or modified within email clients or through external features such as the New-InboxRule or Set-InboxRule PowerShell cmdlets on Windows systems. Affected platforms: Windows, Linux, macOS, Office Suite. MITRE-documented mitigations include M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CM-03, CM-05, CM-07, SI-03, SI-04, SI-07.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-t1564-hide-artifacts"
  ],
  "primary_citations_count": 7
}