Rule Info
Name
Email Protocol Access Via Curl
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects curl.exe being used to access email servers over IMAP or SMTP protocols.
Curl natively supports IMAP/IMAPS and SMTP/SMTPS, allowing attackers to interact with
mailboxes directly from the command line - reading inbox contents, selecting folders,
or sending messages - without deploying a dedicated mail client. This technique is used
for C2 communication via corporate mail infrastructure and for data exfiltration, blending
with legitimate email traffic.
Date
2026-08-27 00:00:00
Modified
None
Id
b2e3f1a0-c4d5-4e6f-2a7b-8c9d0e1f2a3b
Tags
attack.command-and-control attack.t1071.003 attack.exfiltration attack.t1048 attack.collection attack.t1114.002
Type
Nextron Sigma feed only (private)
