{"id":"T1566","name":"Phishing","url":"https://attack.mitre.org/techniques/T1566","tactics":["initial-access"],"platforms":["Identity Provider","Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0070","stix_id":"x-mitre-detection-strategy--7ee73f2e-76b2-4f00-bcc0-7fb79d31d344","name":"Detection Strategy for Phishing across platforms.","url":"https://attack.mitre.org/detectionstrategies/DET0070","analytics":[{"id":"AN0188","stix_id":"x-mitre-analytic--5ea048cd-f1d5-4da2-9128-10c53ee337c8","name":"Analytic 0188","description":"Unusual inbound email activity where attachments or embedded URLs are delivered to users followed by execution of new processes or suspicious document behavior. Detection involves correlating email metadata, file creation, and network activity after a phishing message is received.","url":"https://attack.mitre.org/detectionstrategies/DET0070#AN0188","platforms":["Windows"],"log_source_references":[{"name":"m365:unified","channel":"Send/Receive: Emails with suspicious sender domains, spoofed headers, or anomalous attachment types","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"SuspiciousFileTypes","description":"Attachment types considered high risk (e.g., .exe, .js, .vbs, .scr, macro-enabled docs)."},{"field":"AllowedSenders","description":"Whitelist of known trusted senders to reduce false positives."}],"live":true,"detection_strategies":["DET0070"],"techniques":["T1566"]},{"id":"AN0189","stix_id":"x-mitre-analytic--c5fe5b29-c56f-4c40-b880-051ec6644600","name":"Analytic 0189","description":"Monitor for malicious payload delivery through phishing where attachments or URLs in email clients (e.g., Thunderbird, mutt) result in unusual file creation or outbound network connections. Focus on correlation between mail logs, file writes, and execution activity.","url":"https://attack.mitre.org/detectionstrategies/DET0070#AN0189","platforms":["Linux"],"log_source_references":[{"name":"Application:Mail","channel":"Inbound messages with anomalous headers, spoofed SPF/DKIM failures","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"application-mail"},{"name":"auditd:SYSCALL","channel":"execve: Execution of scripts or binaries sourced from mail directories (/var/mail, ~/Maildir)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"MonitoredMailPaths","description":"System or user directories where emails/attachments are stored."},{"field":"AttachmentHashBaseline","description":"Known good hashes for common business document templates."}],"live":true,"detection_strategies":["DET0070"],"techniques":["T1566"]},{"id":"AN0190","stix_id":"x-mitre-analytic--2a0cc1a9-db3b-4f05-8c85-29d69507418b","name":"Analytic 0190","description":"Detection of phishing through anomalous Mail app activity, such as attachments saved to disk and immediately executed, or Safari/Preview launching URLs and files linked from email messages. Correlate UnifiedLogs events with subsequent process execution.","url":"https://attack.mitre.org/detectionstrategies/DET0070#AN0190","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Inbound email activity with suspicious domains or mismatched sender information","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Preview.app, Safari.app, or Mail.app spawning new processes outside normal patterns","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"SuspiciousDomains","description":"List of domains known for phishing activity or suspicious sender infrastructure."},{"field":"ExecutionDelayWindow","description":"Time threshold between file save and execution considered suspicious."}],"live":true,"detection_strategies":["DET0070"],"techniques":["T1566"]},{"id":"AN0191","stix_id":"x-mitre-analytic--46ecb875-0842-4171-bb36-9b361453a89f","name":"Analytic 0191","description":"Phishing via Office documents containing embedded macros or links that spawn processes. Detection relies on correlating Office application logs with suspicious child process execution and outbound network connections.","url":"https://attack.mitre.org/detectionstrategies/DET0070#AN0191","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"FileAccessed: Access of email attachments by Office applications","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ParentProcessList","description":"Parent processes expected to execute child processes (e.g., Office apps)."},{"field":"MacroExecutionThreshold","description":"Threshold for number of macros executed before raising alerts."}],"live":true,"detection_strategies":["DET0070"],"techniques":["T1566"]},{"id":"AN0192","stix_id":"x-mitre-analytic--09df0b88-e1ae-4a1e-86c4-8bb00e79baed","name":"Analytic 0192","description":"Phishing attempts targeting IdPs often manifest as anomalous login attempts from suspicious email invitations or fake SSO prompts. Detection correlates login flows, MFA bypass attempts, and anomalous geographic patterns following phishing email delivery.","url":"https://attack.mitre.org/detectionstrategies/DET0070#AN0192","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"Failed MFA attempts, unusual conditional access triggers, login attempts from unexpected IP ranges","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"GeoAnomalyThreshold","description":"Allowed distance/time delta between user sign-ins."},{"field":"MFABypassIndicators","description":"Signals of repeated or anomalous MFA failures linked to phishing campaigns."}],"live":true,"detection_strategies":["DET0070"],"techniques":["T1566"]},{"id":"AN0193","stix_id":"x-mitre-analytic--4da63d13-d9bb-41c6-88c8-31bc9f2579fb","name":"Analytic 0193","description":"Phishing delivered via SaaS services (chat, collaboration platforms) where messages contain malicious URLs or attachments. Detect anomalous link clicks, suspicious file uploads, or token misuse after SaaS-based phishing attempts.","url":"https://attack.mitre.org/detectionstrategies/DET0070#AN0193","platforms":["SaaS"],"log_source_references":[{"name":"saas:collaboration","channel":"MessagePosted: Suspicious links or attachment delivery via collaboration tools (Slack, Teams, Zoom)","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-collaboration"}],"mutable_elements":[{"field":"MonitoredSaaSApps","description":"Scope of SaaS platforms under phishing monitoring."},{"field":"LinkInspectionPolicy","description":"Threshold for auto-expansion and detonation of URLs sent in SaaS messages."}],"live":true,"detection_strategies":["DET0070"],"techniques":["T1566"]}],"live":true,"version":"1.0","techniques":["T1566"]}],"sigma_rules":[{"id":"00d0b5ab-1f55-4120-8e83-487c0a7baf19","title":"Download From Suspicious TLD - Blacklist","author":"Florian Roth (Nextron Systems)","status":"test","level":"low","date":"2017-11-07","modified":"2023-05-18","description":"Detects download of certain file types from hosts in suspicious TLDs","references":["https://www.symantec.com/connect/blogs/shady-tld-research-gdn-and-our-2016-wrap","https://promos.mcafee.com/en-US/PDF/MTMW_Report.pdf","https://www.spamhaus.org/statistics/tlds/","https://krebsonsecurity.com/2018/06/bad-men-at-work-please-dont-click/"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.t1566","attack.execution","attack.t1203","attack.t1204.002"],"path":"rules/web/proxy_generic/proxy_download_susp_tlds_blacklist.yml","techniques":["T1566","T1203","T1204.002"],"cves":[]},{"id":"1ae64f96-72b6-48b3-ad3d-e71dff6c6398","title":"Suspicious External WebDAV Execution","author":"Ahmed Farouk","status":"test","level":"high","date":"2024-05-10","modified":null,"description":"Detects executables launched from external WebDAV shares using the WebDAV Explorer integration, commonly seen in initial access campaigns.\n","references":["https://dear-territory-023.notion.site/WebDav-Share-Testing-e4950fa0c00149c3aa430d779b9b1d0f?pvs=4","https://micahbabinski.medium.com/search-ms-webdav-and-chill-99c5b23ac462","https://www.trendmicro.com/en_no/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html","https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.resource-development","attack.t1584","attack.t1566"],"path":"rules/web/proxy_generic/proxy_webdav_external_execution.yml","techniques":["T1584","T1566"],"cves":[]},{"id":"32b5db62-cb5f-4266-9639-0fa48376ac00","title":"CVE-2021-31979 CVE-2021-33771 Exploits","author":"Sittikorn S, frack113","status":"test","level":"critical","date":"2021-07-16","modified":"2023-08-17","description":"Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum","references":["https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/","https://citizenlab.ca/2021/07/hooking-candiru-another-mercenary-spyware-vendor-comes-into-focus/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.initial-access","attack.execution","attack.credential-access","attack.t1566","attack.t1203","cve.2021-33771","cve.2021-31979","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-33771/registry_set_cve_2021_31979_cve_2021_33771_exploits.yml","techniques":["T1566","T1203"],"cves":["CVE-2021-33771","CVE-2021-31979"]},{"id":"38e7f511-3f74-41d4-836e-f57dfa18eead","title":"Potential Malicious Usage of CloudTrail System Manager","author":"jamesc-grafana","status":"test","level":"high","date":"2024-07-11","modified":"2025-12-08","description":"Detect when System Manager successfully executes commands against an instance.\n","references":["https://github.com/elastic/detection-rules/blob/v8.6.0/rules/integrations/aws/initial_access_via_system_manager.toml"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.privilege-escalation","attack.initial-access","attack.t1566","attack.t1566.002"],"path":"rules/cloud/aws/cloudtrail/aws_cloudtrail_ssm_malicious_usage.yml","techniques":["T1566","T1566.002"],"cves":[]},{"id":"4c55738d-72d8-490e-a2db-7969654e375f","title":"WebDAV Temporary Local File Creation","author":"Micah Babinski","status":"test","level":"medium","date":"2023-08-21","modified":null,"description":"Detects the creation of WebDAV temporary files with potentially suspicious extensions","references":["https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html","https://micahbabinski.medium.com/search-ms-webdav-and-chill-99c5b23ac462","https://dear-territory-023.notion.site/WebDav-Share-Testing-e4950fa0c00149c3aa430d779b9b1d0f?pvs=4"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.resource-development","attack.t1584","attack.t1566","detection.threat-hunting"],"path":"rules-threat-hunting/windows/file/file_event/file_event_win_webdav_tmpfile_creation.yml","techniques":["T1584","T1566"],"cves":[]},{"id":"52cad028-0ff0-4854-8f67-d25dfcbc78b4","title":"HTML Help HH.EXE Suspicious Child Process","author":"Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2020-04-01","modified":"2023-04-12","description":"Detects a suspicious child process of a Microsoft HTML Help (HH.exe)","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/chm-badness-delivers-a-banking-trojan/","https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-27939090904026cc396b0b629c8e4314acd6f5dac40a676edbc87f4567b47eb7","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.stealth","attack.t1047","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.007","attack.t1218","attack.t1218.001","attack.t1218.010","attack.t1218.011","attack.t1566","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_html_help_susp_child_process.yml","techniques":["T1047","T1059.001","T1059.003","T1059.005","T1059.007","T1218","T1218.001","T1218.010","T1218.011","T1566","T1566.001"],"cves":[]},{"id":"6e4dcdd1-e48b-42f7-b2d8-3b413fc58cb4","title":"Suspicious Execution via macOS Script Editor","author":"Tim Rauch (rule), Elastic (idea)","status":"test","level":"medium","date":"2022-10-21","modified":"2022-12-28","description":"Detects when the macOS Script Editor utility spawns an unusual child process.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-7f541fbc4a4a28a92970e8bf53effea5bd934604429112c920affb457f5b2685","https://wojciechregula.blog/post/macos-red-teaming-initial-access-via-applescript-url/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1566","attack.t1566.002","attack.initial-access","attack.t1059","attack.t1059.002","attack.t1204","attack.t1204.001","attack.execution","attack.persistence","attack.t1553"],"path":"rules/macos/process_creation/proc_creation_macos_susp_execution_macos_script_editor.yml","techniques":["T1566","T1566.002","T1059","T1059.002","T1204","T1204.001","T1553"],"cves":[]},{"id":"ad7085ac-92e4-4b76-8ce2-276d2c0e68ef","title":"CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum","author":"Sittikorn S","status":"test","level":"critical","date":"2021-07-16","modified":"2022-10-09","description":"Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum","references":["https://www.microsoft.com/security/blog/2021/07/15/protecting-customers-from-a-private-sector-offensive-actor-using-0-day-exploits-and-devilstongue-malware/","https://citizenlab.ca/2021/07/hooking-candiru-another-mercenary-spyware-vendor-comes-into-focus/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.execution","attack.credential-access","attack.t1566","attack.t1203","cve.2021-33771","cve.2021-31979","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-33771/file_event_win_cve_2021_31979_cve_2021_33771_exploits.yml","techniques":["T1566","T1203"],"cves":["CVE-2021-33771","CVE-2021-31979"]},{"id":"b5de2919-b74a-4805-91a7-5049accbaefe","title":"Download From Suspicious TLD - Whitelist","author":"Florian Roth (Nextron Systems)","status":"test","level":"low","date":"2017-03-13","modified":"2023-05-18","description":"Detects executable downloads from suspicious remote systems","references":["Internal Research"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.t1566","attack.execution","attack.t1203","attack.t1204.002"],"path":"rules/web/proxy_generic/proxy_download_susp_tlds_whitelist.yml","techniques":["T1566","T1203","T1204.002"],"cves":[]},{"id":"c27515df-97a9-4162-8a60-dc0eeb51b775","title":"Suspicious Microsoft OneNote Child Process","author":"Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Elastic (idea)","status":"test","level":"high","date":"2022-10-21","modified":"2023-02-10","description":"Detects suspicious child processes of the Microsoft OneNote application. This may indicate an attempt to execute malicious embedded objects from a .one file.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-e34e43eb5666427602ddf488b2bf3b545bd9aae81af3e6f6c7949f9652abdf18","https://micahbabinski.medium.com/detecting-onenote-one-malware-delivery-407e9321ecf0"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1566","attack.t1566.001","attack.initial-access"],"path":"rules/windows/process_creation/proc_creation_win_office_onenote_susp_child_processes.yml","techniques":["T1566","T1566.001"],"cves":[]},{"id":"dbbd9f66-2ed3-4ca2-98a4-6ea985dd1a1c","title":"Potential Initial Access via DLL Search Order Hijacking","author":"Tim Rauch (rule), Elastic (idea)","status":"test","level":"medium","date":"2022-10-21","modified":null,"description":"Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-5d46dd4ac6866b4337ec126be8cee0e115467b3e8703794ba6f6df6432c806bc","https://posts.specterops.io/automating-dll-hijack-discovery-81c4295904b0"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1566","attack.t1566.001","attack.initial-access","attack.t1574","attack.t1574.001"],"path":"rules/windows/file/file_event/file_event_win_initial_access_dll_search_order_hijacking.yml","techniques":["T1566","T1566.001","T1574","T1574.001"],"cves":[]},{"id":"e8a95b5e-c891-46e2-b33a-93937d3abc31","title":"Suspicious HH.EXE Execution","author":"Maxim Pavlunin","status":"test","level":"high","date":"2020-04-01","modified":"2023-04-12","description":"Detects a suspicious execution of a Microsoft HTML Help (HH.exe)","references":["https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/chm-badness-delivers-a-banking-trojan/","https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-27939090904026cc396b0b629c8e4314acd6f5dac40a676edbc87f4567b47eb7","https://www.ptsecurity.com/ww-en/analytics/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/","https://www.zscaler.com/blogs/security-research/unintentional-leak-glimpse-attack-vectors-apt37"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.initial-access","attack.stealth","attack.t1047","attack.t1059.001","attack.t1059.003","attack.t1059.005","attack.t1059.007","attack.t1218","attack.t1218.001","attack.t1218.010","attack.t1218.011","attack.t1566","attack.t1566.001"],"path":"rules/windows/process_creation/proc_creation_win_hh_susp_execution.yml","techniques":["T1047","T1059.001","T1059.003","T1059.005","T1059.007","T1218","T1218.001","T1218.010","T1218.011","T1566","T1566.001"],"cves":[]},{"id":"ee39a9f7-5a79-4b0a-9815-d36b3cf28d3e","title":"Okta FastPass Phishing Detection","author":"Austin Songer @austinsonger","status":"test","level":"high","date":"2023-05-07","modified":"2026-04-27","description":"Detects when Okta FastPass prevents a known phishing site.","references":["https://sec.okta.com/fastpassphishingdetection","https://developer.okta.com/docs/reference/api/system-log/","https://developer.okta.com/docs/reference/api/event-types/"],"logsource":{"product":"okta","service":"okta"},"tags":["attack.initial-access","attack.t1566"],"path":"rules/identity/okta/okta_fastpass_phishing_detection.yml","techniques":["T1566"],"cves":[]},{"id":"fcdf69e5-a3d3-452a-9724-26f2308bf2b1","title":"Phishing Pattern ISO in Archive","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-06-07","modified":null,"description":"Detects cases in which an ISO files is opend within an archiver like 7Zip or Winrar, which is a sign of phishing as threat actors put small ISO files in archives as email attachments to bypass certain filters and protective measures (mark of web)","references":["https://twitter.com/1ZRR4H/status/1534259727059787783","https://app.any.run/tasks/e1fe6a62-bce8-4323-a49a-63795d9afd5d/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1566"],"path":"rules/windows/process_creation/proc_creation_win_susp_archiver_iso_phishing.yml","techniques":["T1566"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-11182","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2025-24054","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-36884","state":"stale","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-41128","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2022-34713","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2021-40449","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}