Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.
All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
Deploy Mimecast Targeted Threat Protection including URL Protect, Attachment Protect, Impersonation Protect, and Internal Email Protect to defend against advanced phishing and spearphishing attacks.
cybersecurity
phishing-defense
mimecast
email-security
targeted-threat-protection
url-protect
impersonation
attachment-sandboxing
phishing
1.0
mahipal
Apache-2.0
PR.AT-01
DE.CM-09
RS.CO-02
DE.AE-02
Implementing Mimecast Targeted Attack Protection
Overview
Mimecast Targeted Threat Protection (TTP) is a suite of advanced email security services designed to protect against sophisticated phishing, spearphishing, and targeted attacks. TTP consists of four core modules: URL Protect (real-time URL rewriting and click-time analysis), Attachment Protect (sandbox detonation of suspicious attachments), Impersonation Protect (BEC and whaling detection), and Internal Email Protect (scanning internal/outbound email for threats). As of November 2025, Mimecast enabled URL Pre-Delivery Action with Hold setting for all customers by default.
When to Use
When deploying or configuring implementing mimecast targeted attack protection capabilities in your environment
When establishing security controls aligned to compliance requirements
When building or improving security architecture for this domain
When conducting security assessments that require this implementation
Prerequisites
Mimecast Email Security license with TTP add-on
Administrative access to Mimecast Administration Console
Microsoft 365 or Google Workspace environment
MX records configured to route through Mimecast
Understanding of email authentication (SPF, DKIM, DMARC)
Key Concepts
TTP Module Overview
Module
Function
Key Capability
URL Protect
Rewrites and scans URLs at click time
Real-time sandbox, pre-delivery hold
Attachment Protect
Sandboxes suspicious attachments
Static + dynamic analysis
Impersonation Protect
Detects BEC/whaling attacks
VIP name matching, header analysis
Internal Email Protect
Scans internal/outbound email
Lateral phishing detection
Impersonation Protection Scenarios
Hit 3 (Default): Flags emails matching 3+ impersonation indicators
Hit 1 (VIP): Flags emails matching 1+ indicator for designated VIP users