Windows PowerShell Script Accessing Windows MailApp MailBox Data Path

Identifies PowerShell scripts referencing the Windows MailApp mailbox data path, which may indicate email data access or manipulation.

FreeReviewedSigma · Medium · v5
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2023-07-08
Updated
2026-07-31

ATT&CK techniques

Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies PowerShell scripts whose contents reference the Windows MailApp Unistore mailbox data directory. Accessing these stored mailbox files can enable attackers to view, manipulate, exfiltrate, or delete user email content. The detection relies on PowerShell script block text containing a specific mailbox data path fragment.

Related detections2 linkedT1070.008 — drag to rearrange
Suspicious Teams Message Soft Delete by Agent Identity via M365 Audit
Unusual Access to Windows Outlook Unistore Mail Data by Non-Standard Processes
Windows PowerShell Script Accessing Windows MailApp MailBox Data Path
Pivot detection · T1070.008 · 2 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.