Rules by Product and UseCase

April 15, 2026 · View on GitHub

Vendor: Postfix

Product: Postfix

Use-Case: Phishing

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
11212
Event TypeRulesModels
dlp-email-alert-outT1048 - Exfiltration Over Alternative Protocol
EM-OD-A: Abnormal email domain for organization

T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
EM-OD-A: Abnormal email domain for organization
EM-OD: Domains per organization