What MITRE ATT&CK T1684.002: Email Spoofing (Enterprise Tactic TA0005 - Stealth) requires
MITRE ATT&CK T1684.002 (Email Spoofing) is an Enterprise Stealth technique. Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses. In addition to actual email content, email headers (such as the FROM header, which contains the email address of the sender) may also be modified. Email clients display these headers when emails appear in a victim's inbox, which may cause modified emails to appear as if they were from the spoofed entity. Enterprise environments can use Domain-based Message Authentication, Reporting, and Conformance (DMARC) as an email authentication protocol that references results of the Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) configurations. SPF and DKIM are configured separately in DNS: SPF verifies that the sen... Affected platforms: Linux, macOS, Office Suite, Windows. Sub-technique of ATT&CK T1684. ATT&CK-mapped mitigations: M1054 Software Configuration.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1684/002/
SHA-256 integrity: 5bea93b7ce3e42d4fa3f8b80c1ed73bf012494ff45193908eca7bc605ce3625b
Primary Citations — 5 traced to source
- MITRE ATT&CK Technique T1684.002: Email Spoofing (https://attack.mitre.org/techniques/T1684/002/)
- MITRE ATT&CK Tactic TA0005: Stealth (https://attack.mitre.org/tactics/TA0005/)
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.