{"id":"T1566.003","name":"Spearphishing via Service","url":"https://attack.mitre.org/techniques/T1566/003","tactics":["initial-access"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0115","stix_id":"x-mitre-detection-strategy--dd232215-bb7f-461f-ac3f-e7cf5612e396","name":"Detection Strategy for Spearphishing via a Service across OS Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0115","analytics":[{"id":"AN0320","stix_id":"x-mitre-analytic--c83f1d8c-ba54-4f2d-91b8-3006a2180497","name":"Analytic 0320","description":"Inbound spearphishing attempts delivered via third-party services (e.g., Gmail, LinkedIn messages) leading to malicious file downloads or browser-initiated script execution. Defender view includes correlation of external service logins, unexpected file write operations, and suspicious descendant processes spawned from productivity or browser applications.","url":"https://attack.mitre.org/detectionstrategies/DET0115#AN0320","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"MonitoredServices","description":"List of third-party services (e.g., Gmail, LinkedIn, Dropbox) relevant to the organization’s threat profile."},{"field":"SuspiciousProcessPatterns","description":"Process lineage and parent-child execution relationships considered abnormal (e.g., outlook.exe → powershell.exe)."},{"field":"TimeWindow","description":"Correlates file creation and outbound connection activity within a tunable time period after message receipt."}],"live":true,"detection_strategies":["DET0115"],"techniques":["T1566.003"]},{"id":"AN0321","stix_id":"x-mitre-analytic--eed7a6f2-496d-47c6-bdfd-1b885b58a651","name":"Analytic 0321","description":"Use of non-enterprise email or messaging services in Thunderbird, Evolution, or browsers leading to suspicious file downloads and subsequent execution. Defender view includes browser-initiated downloads of unexpected content and shell or interpreter processes launched post-download.","url":"https://attack.mitre.org/detectionstrategies/DET0115#AN0321","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of bash, python, or perl processes spawned by browser/email client","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Inbound messages from webmail services containing attachments or URLs","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"},{"name":"NSM:Flow","channel":"Outbound traffic to domains/IPs not previously resolved, occurring shortly after attachment download or link click","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"BrowserProcesses","description":"Configured list of browsers or email clients to monitor (e.g., firefox, chromium, thunderbird)."},{"field":"PhishingIndicators","description":"Custom regex rules for suspicious URL patterns, file extensions, or encoded links."}],"live":true,"detection_strategies":["DET0115"],"techniques":["T1566.003"]},{"id":"AN0322","stix_id":"x-mitre-analytic--262ce2a7-2c09-4f6d-8e9f-de57b814a2a2","name":"Analytic 0322","description":"Phishing attempts via iCloud Mail, Gmail, or social media apps accessed on macOS systems. Defender view includes Mail.app or Safari downloads of files followed by osascript, Terminal, or abnormal child process execution.","url":"https://attack.mitre.org/detectionstrategies/DET0115#AN0322","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Received messages containing embedded links or attachments from non-enterprise services","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Execution of osascript, bash, or Terminal initiated from Mail.app or Safari","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Suspicious outbound HTTPS requests to domains flagged as newly registered or untrusted after spearphishing message interaction","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"CertificateChecks","description":"Flagging mismatched or self-signed certificates during outbound connections initiated after spearphishing messages."},{"field":"ExecutionDelay","description":"Window of time between attachment download and subsequent suspicious execution."}],"live":true,"detection_strategies":["DET0115"],"techniques":["T1566.003"]}],"live":true,"version":"1.0","techniques":["T1566.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}