{"id":"T1534","name":"Internal Spearphishing","url":"https://attack.mitre.org/techniques/T1534","tactics":["lateral-movement"],"platforms":["Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0054","stix_id":"x-mitre-detection-strategy--acc27d20-8aad-42ce-b928-6cda3c22e51b","name":"Internal Spearphishing via Trusted Accounts","url":"https://attack.mitre.org/detectionstrategies/DET0054","analytics":[{"id":"AN0147","stix_id":"x-mitre-analytic--0bf5b548-50d0-4e73-bb3c-413cbdfafd97","name":"Analytic 0147","description":"Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts.","url":"https://attack.mitre.org/detectionstrategies/DET0054#AN0147","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4625","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Security","channel":"EventCode=4672","data_component":"DC0088","data_component_name":"Logon Session Metadata","log_source_slug":"wineventlog-security"},{"name":"m365:unified","channel":"SendOnBehalf, MessageSend, ClickThrough, MailItemsAccessed","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Expected time between internal email and link execution or file dropper"},{"field":"UserContext","description":"Baseline logon locations and device usage for sender accounts"},{"field":"AttachmentEntropyThreshold","description":"Entropy value over which attachment is considered suspicious"}],"live":true,"detection_strategies":["DET0054"],"techniques":["T1534"]},{"id":"AN0148","stix_id":"x-mitre-analytic--b5b53b9d-f72b-4cd5-946b-d1ddfdad3c0f","name":"Analytic 0148","description":"Delivery of suspicious internal communication (e.g., Thunderbird, Evolution) using compromised internal accounts. Sequence of: unexpected user activity + mail transfer logs + download or execution of attachments.","url":"https://attack.mitre.org/detectionstrategies/DET0054#AN0148","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"Application:Mail","channel":"smtpd$.*$: .*from=[.*@internaldomain.com](mailto:.*@internaldomain.com) to=[.*@internaldomain.com](mailto:.*@internaldomain.com)","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"application-mail"},{"name":"linux:syslog","channel":"curl|wget|python .*http","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"SubjectLineAnomaly","description":"Deviation from typical internal email subjects"},{"field":"AttachmentType","description":"Executable types allowed or flagged by mail relay"}],"live":true,"detection_strategies":["DET0054"],"techniques":["T1534"]},{"id":"AN0149","stix_id":"x-mitre-analytic--3533fba3-e80d-4ad0-be45-62460b28ad7c","name":"Analytic 0149","description":"Abnormal Apple Mail use, including internal email relays followed by file execution or script events (e.g., attachments launched via Preview, terminal triggered from Mail.app)","url":"https://attack.mitre.org/detectionstrategies/DET0054#AN0149","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"com.apple.mail.* exec.*","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"curl|osascript.*open location","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ExecutionChainDepth","description":"Number of child processes stemming from Mail.app"},{"field":"MailScriptFlag","description":"Toggle on scripting detection within mail context"}],"live":true,"detection_strategies":["DET0054"],"techniques":["T1534"]},{"id":"AN0150","stix_id":"x-mitre-analytic--1e2211b9-1730-4645-89f6-11259b35e0a4","name":"Analytic 0150","description":"Internal spearphishing via SaaS applications (e.g., Slack, Teams, Gmail): message sent from compromised user with attachment or URL, followed by click and credential access behavior.","url":"https://attack.mitre.org/detectionstrategies/DET0054#AN0150","platforms":["SaaS"],"log_source_references":[{"name":"saas:slack","channel":"file_upload, message_send, message_click","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-slack"}],"mutable_elements":[{"field":"UserAnomalyThreshold","description":"Volume or timing of messages sent after compromise"},{"field":"FileRiskScoring","description":"Whether SaaS DLP assigns risk scores to attachments"}],"live":true,"detection_strategies":["DET0054"],"techniques":["T1534"]},{"id":"AN0151","stix_id":"x-mitre-analytic--5e3f407f-192b-4e6f-aab0-e0682da3a4a9","name":"Analytic 0151","description":"Outlook or Word used to forward suspicious internal attachments with macro content. Defender observes attachment forwarding, auto-opening behaviors, or macro prompt interactions.","url":"https://attack.mitre.org/detectionstrategies/DET0054#AN0151","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"SendOnBehalf, MessageSend, AttachmentPreviewed","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"WinEventLog:Security","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"MacroExecutionWindow","description":"Timing between mail open and macro invocation"},{"field":"AttachmentNameHeuristics","description":"Patterns of known internal spearphishing lures (e.g., invoice, HR_policy)"}],"live":true,"detection_strategies":["DET0054"],"techniques":["T1534"]}],"live":true,"version":"1.0","techniques":["T1534"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}