T1566 Phishing
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Droppers Exploiting CVE-2017-11882criticalstable · windows
- Ursnif Malware C2 URL Patterncriticalstable · proxy
- CVE-2021-31979 CVE-2021-33771 Exploitscriticaltest · windows
- CVE-2021-31979 CVE-2021-33771 Exploits by Sourgumcriticaltest · windows
- Exploit for CVE-2017-8759criticaltest · windows
- Suspicious Double Extension File Executionhighstable · windows
- HTML Help HH.EXE Suspicious Child Processhightest · windows
- ISO File Created Within Temp Foldershightest · windows
- Office Macro File Creation From Suspicious Processhightest · windows
- Okta FastPass Phishing Detectionhightest · okta
- Password Protected ZIP File Opened (Email Attachment)hightest · windows
- Phishing Pattern ISO in Archivehightest · windows
- Potential Malicious Usage of CloudTrail System Managerhightest · aws
- Suspicious Execution From Outlook Temporary Folderhightest · windows
- Suspicious External WebDAV Executionhightest · proxy
- Suspicious HH.EXE Executionhightest · windows
- Suspicious HWP Sub Processeshightest · windows
- Suspicious Microsoft OneNote Child Processhightest · windows
- Suspicious File Created in Outlook Temporary Directoryhighexperimental · windows
- Arbitrary Shell Command Execution Via Settingcontent-Msmediumtest · windows
- Disk Image Mounting Via Hdiutil - MacOSmediumtest · macos
- Exploit for CVE-2017-0261mediumtest · windows
- ISO Image Mountedmediumtest · windows
- ISO or Image Mount Indicator in Recent Filesmediumtest · windows
- Potential Initial Access via DLL Search Order Hijackingmediumtest · windows
Mostrando 25 de 28.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.