Vendor: Postfix
April 15, 2026 · View on GitHub
Product: Postfix
| Rules | Models | MITRE ATT&CK® TTPs | Activity Types | Parsers |
|---|---|---|---|---|
| 57 | 24 | 8 | 4 | 3 |
| Use-Case | Activity Types/Parsers | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Data Leak | dlp-email-alert-out ↳postfix-postfix-str-email-subject ↳postfix-postfix-kv-email-queue ↳postfix-postfix-mix-email-sent dlp-email-alert-out-failed ↳postfix-postfix-str-email-send-fail-statusdeferred ↳postfix-postfix-str-email-send-fail-deliveryfailure | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Lateral Movement | network-connection-failed ↳postfix-postfix-str-smtp-close-connectionfail | T1090 - Proxy T1090.003 - Proxy: Multi-hop Proxy T1190 - Exploit Public Fasing Application TA0010 - TA0010 TA0011 - TA0011 |
|
| Phishing | dlp-email-alert-out ↳postfix-postfix-str-email-subject ↳postfix-postfix-kv-email-queue ↳postfix-postfix-mix-email-sent | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Workforce Protection | dlp-email-alert-out ↳postfix-postfix-str-email-subject ↳postfix-postfix-kv-email-queue ↳postfix-postfix-mix-email-sent | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Next Page -->> |
MITRE ATT&CK® Framework for Enterprise
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Valid Accounts Exploit Public Fasing Application | Valid Accounts | Valid Accounts | Valid Accounts | Proxy: Multi-hop Proxy Proxy | Exfiltration Over Alternative Protocol Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |