The sub-techniques beta is now live! Read the release blog post for more info.


MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used by a non-administrative user to search their own email, or by an Exchange administrator to search the mailboxes of every user in a domain.[1]

ID: S0413
Type: TOOL
Platforms: Office 365, Windows, Azure AD
Version: 1.0
Created: 05 October 2019
Last Modified: 15 October 2019

Techniques Used

Domain ID Name Use
Enterprise T1087 Account Discovery

MailSniper can be used to obtain account names from Exchange and Office 365 using the Get-GlobalAddressList cmdlet.[2]

Enterprise T1110 Brute Force

MailSniper can be used for password spraying against Exchange and Office 365.[1]

Enterprise T1114 Email Collection

MailSniper can be used for searching through email in Exchange and Office 365 environments.[1]

Groups That Use This Software

ID Name References
G0077 Leafminer [3]