T1114 Email Collection via non-standard POP3/IMAP clients
This rule detects processes initiating network connections to standard POP3 (110, 995) and IMAP (143, 993) ports that are not identified as trusted, well-known mail clients. By filtering out connections from common email application paths and local IP ranges, it aims to identify potentially malicious processes, scripts, or non-standard tools attempting to perform email collection or exfiltration directly from mail servers.
Microsoft Sentinel (KQL)

