What MITRE ATT&CK T1589.002: Email Addresses (Enterprise Tactic TA0043 - Reconnaissance) requires
MITRE ATT&CK T1589.002 (Email Addresses) is an Enterprise Reconnaissance sub-technique of T1589 (Gather Victim Identity Information). Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email infrastructure and addresses for employees. Adversaries may easily gather email addresses, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Email addresses could also be enumerated via more active means (i.e. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1589/002/
SHA-256 integrity: 91dab7e2520730852f8e64bf8a63b468ec1ee88cc45868b9665060c55a8f5ac9
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1589.002: Email Addresses (https://attack.mitre.org/techniques/T1589/002/)
- MITRE ATT&CK Tactic TA0043: Reconnaissance (https://attack.mitre.org/tactics/TA0043/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1589-002-email-addresses.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1589-002-email-addresses.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1589-002-email-addresses
- Back to registry: Browse all 10,085 compliance nodes