What It Does
Remove a delivered malicious message from every mailbox it reached, including forwards and delegated copies, rather than only from the originally reported one.
Observable indicator. A reported message is removed estate-wide, not only where it was reported.
Where It Sits
A technique is chosen from inside a form and emplaced on one layer. Both are the catalog’s own declarations; the position is counted in catalog order.
- Form of maneuverM7 CounterattackSeize the initiative and evict before the adversary reaches the objective.
- Terrain layerT4 Applications and WorkloadsThe urban terrain. Key terrain: The public service portal, the case processing system, public APIs.
- Position in the form17 of 17M7 carries 17 cataloged techniques; this is the 17th in catalog order.
Phases It Is Employed In
Employed in one phase of the campaign. A phase named here means at least this technique is live in it — not that the form it belongs to is the main effort.
- Phase IIIDominateHunt, contain, evict.
Controls That Assess It
The controls the catalog names against this technique. They are what an assessor would test to establish that it is emplaced and working — the indicator above is what shows it is working, which is a different question.
- EN-5 Eradication and Transition to RecoveryEngagement and Pursuit — To ensure the adversary is actually gone before the mission is restored, and that the transition is a decision rather than a drift.
- TA-4 Pre-authorized ResponseTempo and Temporal Advantage — To remove authority latency from the decision loop, so that the segment most programs cannot shorten with tooling is shortened by governance.
- DV-3 Endpoint Sensor Coverage and LivenessDevices Terrain — To know what the estate can actually see, and to detect the loss of that visibility as an event rather than at the next assessment.
In MITRE D3FEND
What this technique is called in MITRE’s countermeasure ontology. The join runs technique-to-technique: D3FEND catalogs countermeasures, and the thing with a countermeasure’s shape here is the technique, not the control.
- D3-EF Email FilteringIsolate tactic
- D3-ER Email RemovalEvict tactic
That a technique reaches a D3FEND countermeasure says the two describe the same defensive act. It does not say the countermeasure is deployed, configured, or working — that is an assessment finding about your estate, not a property of the framework.
Related Techniques
The catalog declares no relation for this entry, and no other entry names it — the inverse is derived here, so an incoming edge would show up even though this one never declared it. The techniques below share its assessment surface, which is the nearest adjacency the data supports.
Assessed Alongside
Not a declared relation: these are the techniques whose assessing controls overlap this one’s, ranked by how much of the two assessment surfaces coincide. Showing 6 of 23 that share at least one control.
- 1 shared controlM1.06 Credential Exposure MonitoringM1 Screen / Guard · T1 Identity
- TA-4
- 1 shared controlM7.05 Credential Reset SweepM7 Counterattack · T1 Identity
- TA-4
- 1 shared controlM8.05 Federation Trust SuspensionM8 Isolation / Retrograde · T1 Identity
- TA-4
- 1 shared controlM8.06 Cloud Account QuarantineM8 Isolation / Retrograde · T4 Applications and Workloads
- TA-4
- 1 shared controlM8.07 Egress BlackholeM8 Isolation / Retrograde · T3 Networks
- TA-4
- 1 shared controlM9.01 Advisory-Driven Pre-BlockingM9 Spoiling Attack · TX Cross-Cutting
- TA-4