Rules by Product and UseCase

April 15, 2026 · View on GitHub

Vendor: BeyondTrust

Product: BeyondInsight

Use-Case: Data Leak

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
302115
Event TypeRulesModels
app-activityT1114 - Email Collection
EM-InRule-EX: User has created an inbox forwarding rule to forward email to an external domain email
EM-InRule-Public: User has created an inbox forwarding rule to forward email to a public email domain
EM-InRule-Fin: User has created an inbox forwarding rule to forward emails containing financial keywords

T1114.003 - Email Collection: Email Forwarding Rule
EM-InRule-EX: User has created an inbox forwarding rule to forward email to an external domain email
EM-InRule-Public: User has created an inbox forwarding rule to forward email to a public email domain
EM-InRule-Fin: User has created an inbox forwarding rule to forward emails containing financial keywords