kevmap

TechniquesT1566 › AN0188

AN0188 Analytic 0188

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Unusual inbound email activity where attachments or embedded URLs are delivered to users followed by execution of new processes or suspicious document behavior. Detection involves correlating email metadata, file creation, and network activity after a phishing message is received.</p>
Detects
T1566 Phishing
Part of
DET0070 Detection Strategy for Phishing across platforms.

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:unifiedSend/Receive: Emails with suspicious sender domains, spoofed headers, or anomalous attachment typesDC0038 Application Log Content
WinEventLog:SysmonEventCode=11DC0039 File Creation
WinEventLog:SysmonEventCode=1DC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
SuspiciousFileTypesAttachment types considered high risk (e.g., .exe, .js, .vbs, .scr, macro-enabled docs).
AllowedSendersWhitelist of known trusted senders to reduce false positives.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-40449Microsoft WindowsMapped
CVE-2022-34713Microsoft WindowsMapped
CVE-2022-41128Microsoft WindowsMapped
CVE-2023-36884Microsoft WindowsStale
CVE-2024-11182MDaemon Email ServerMapped
CVE-2025-24054Microsoft WindowsMapped