Gathered victim email address information for follow-on phishing activity.1
Email Addresses T1589.002
- Tactic
- Reconnaissance
- Platform
- PRE
- Version
- 1.3
- Created
- 02 October 2020
- Last modified
- 12 May 2026
- Contributor
- Jannie Li, Microsoft Threat Intelligence Center (MSTIC)
Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email infrastructure and addresses for employees.
Email Addresses MITRE reference T1589.002
14 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Gathered victim email information in advance of phishing operations for targeted attacks.1
Has targeted the personal emails of key network and IT staff at victim organizations.1
Has gathered targeted individuals' e-mail addresses through open source research and website contact forms.1
Has gathered employee email addresses, including personal accounts, for social engineering and initial access efforts.1
Has used spoofed company emails that were acquired from email clients on previously infected hosts to target other individuals.1
All 14 groups for this technique · 6 newest in this preview
2 campaigns have been recorded using this technique. Listed newest first; dates are year-granularity and attribution is MITRE’s.
Has gathered targeted individual’s e-mail addresses for the password spraying attempts.1
Utilizes thread spoofing of existing email threads in order to execute spear phishing operations.1
All 2 campaigns for this technique
Offense vs defense T1589.002
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
How it got here
Adversary activity (campaign spans) over cumulative rule output. Each source is plotted independently from zero, so neither line includes the other. Campaign dates are year-granularity.
Email Addresses detection strategy DET0814
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Email Addresses
AN1946 · PRE
Monitor for suspicious network traffic that could be indicative of probing for email addresses and/or usernames, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.
Log sources
The data this analytic draws on. You do not need every component — each one you already collect covers part of it. Each links to its ATT&CK record.
| Data component | Name | Channel |
|---|---|---|
| Network Traffic ContentDC0085 | Network Traffic | None |
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls. Efforts should focus on minimizing the amount and sensitivity of data available to external parties.