Compliance Node Overview
MITRE ATT&CK T1114.001 (Local Email Collection) is an Enterprise Collection sub-technique of T1114 (Email Collection). Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user's local system, such as Outlook storage or cache files. Outlook stores data locally in offline data files with an extension of .ost. Outlook 2010 and later supports .ost file sizes up to 50GB, while earlier versions of Outlook support up to 20GB. Affected platforms: Windows. MITRE-documented mitigations include M1060 Out-of-Band Communications Channel, M1041 Encrypt Sensitive Information. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-04, AC-16, AC-17, AC-19, AC-20, CM-02, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1114/001/
SHA-256 integrity: 849cdb068cdd23778497b1e27bdee7e786a46ab7edfda12132ddba9d4deceb67
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1114.001: Local Email Collection (https://attack.mitre.org/techniques/T1114/001/)
- MITRE ATT&CK Tactic TA0009: Collection (https://attack.mitre.org/tactics/TA0009/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access