T1566.001 Spearphishing Attachment
Subtécnica de T1566 Phishing
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Droppers Exploiting CVE-2017-11882criticalstable · windows
- Ursnif Malware C2 URL Patterncriticalstable · proxy
- Exploit for CVE-2017-8759criticaltest · windows
- Suspicious Double Extension File Executionhighstable · windows
- HTML Help HH.EXE Suspicious Child Processhightest · windows
- ISO File Created Within Temp Foldershightest · windows
- Office Macro File Creation From Suspicious Processhightest · windows
- Password Protected ZIP File Opened (Email Attachment)hightest · windows
- Suspicious Execution From Outlook Temporary Folderhightest · windows
- Suspicious HH.EXE Executionhightest · windows
- Suspicious HWP Sub Processeshightest · windows
- Suspicious Microsoft OneNote Child Processhightest · windows
- Suspicious File Created in Outlook Temporary Directoryhighexperimental · windows
- Arbitrary Shell Command Execution Via Settingcontent-Msmediumtest · windows
- Disk Image Mounting Via Hdiutil - MacOSmediumtest · macos
- Exploit for CVE-2017-0261mediumtest · windows
- ISO Image Mountedmediumtest · windows
- ISO or Image Mount Indicator in Recent Filesmediumtest · windows
- Potential Initial Access via DLL Search Order Hijackingmediumtest · windows
- Windows Registry Trust Record Modificationmediumtest · windows
- Suspicious Email Delivered In Microsoft 365mediumexperimental · m365
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.