Techniques › T1534 › AN0147
AN0147 Analytic 0147
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts.</p>
- Detects
- T1534 Internal Spearphishing
- Part of
- DET0054 Internal Spearphishing via Trusted Accounts
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| WinEventLog:Security | EventCode=4624, 4648 | DC0067 Logon Session Creation |
| WinEventLog:Security | EventCode=4625 | DC0002 User Account Authentication |
| WinEventLog:Security | EventCode=4672 | DC0088 Logon Session Metadata |
| m365:unified | SendOnBehalf, MessageSend, ClickThrough, MailItemsAccessed | DC0038 Application Log Content |
| WinEventLog:Sysmon | EventCode=1 | DC0032 Process Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
TimeWindow | Expected time between internal email and link execution or file dropper |
UserContext | Baseline logon locations and device usage for sender accounts |
AttachmentEntropyThreshold | Entropy value over which attachment is considered suspicious |