Compliance Node Overview
MITRE ATT&CK T1564.008 (Email Hiding Rules) is an Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow users to create inbox rules for various email functions, including moving emails to other folders, marking emails as read, or deleting emails. Rules may be created or modified within email clients or through external features such as the New-InboxRule or Set-InboxRule PowerShell cmdlets on Windows systems. Affected platforms: Windows, Linux, macOS, Office Suite. MITRE-documented mitigations include M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CM-03, CM-05, CM-07, SI-03, SI-04, SI-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1564/008/
SHA-256 integrity: 3c3966271ebb341e898e10f204e96316f63019351d09f92fd9c117393e050da4
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1564.008: Email Hiding Rules (https://attack.mitre.org/techniques/T1564/008/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access