Techniques › T1566 › AN0188
AN0188 Analytic 0188
Windows · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Unusual inbound email activity where attachments or embedded URLs are delivered to users followed by execution of new processes or suspicious document behavior. Detection involves correlating email metadata, file creation, and network activity after a phishing message is received.</p>
- Detects
- T1566 Phishing
- Part of
- DET0070 Detection Strategy for Phishing across platforms.
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| m365:unified | Send/Receive: Emails with suspicious sender domains, spoofed headers, or anomalous attachment types | DC0038 Application Log Content |
| WinEventLog:Sysmon | EventCode=11 | DC0039 File Creation |
| WinEventLog:Sysmon | EventCode=1 | DC0032 Process Creation |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
SuspiciousFileTypes | Attachment types considered high risk (e.g., .exe, .js, .vbs, .scr, macro-enabled docs). |
AllowedSenders | Whitelist of known trusted senders to reduce false positives. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2021-40449 | Microsoft Windows | Mapped |
| CVE-2022-34713 | Microsoft Windows | Mapped |
| CVE-2022-41128 | Microsoft Windows | Mapped |
| CVE-2023-36884 | Microsoft Windows | Stale |
| CVE-2024-11182 | MDaemon Email Server | Mapped |
| CVE-2025-24054 | Microsoft Windows | Mapped |