{"id":"T1566.002","name":"Spearphishing Link","url":"https://attack.mitre.org/techniques/T1566/002","tactics":["initial-access"],"platforms":["Identity Provider","Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0107","stix_id":"x-mitre-detection-strategy--ed58a144-2554-495c-9c60-18e6f817aa75","name":"Detection Strategy for Spearphishing Links","url":"https://attack.mitre.org/detectionstrategies/DET0107","analytics":[{"id":"AN0298","stix_id":"x-mitre-analytic--a39fccda-e5ea-49de-80f9-d67ae3b8c799","name":"Analytic 0298","description":"Correlation of inbound emails with embedded links followed by user-driven browser navigation to suspicious or obfuscated domains. Detection chain includes malicious URL in email → user click recorded in Office logs → browser process spawning unusual child processes (e.g., PowerShell, cmd) or download activity.","url":"https://attack.mitre.org/detectionstrategies/DET0107#AN0298","platforms":["Windows"],"log_source_references":[{"name":"m365:unified","channel":"Send/Receive: Inbound emails containing embedded or shortened URLs","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"SuspiciousTLDs","description":"List of monitored top-level domains commonly abused in phishing (e.g., .xyz, .top, .tk)."},{"field":"URLShortenerDomains","description":"Domains like bit.ly, tinyurl.com flagged for deeper expansion/inspection."},{"field":"ClickToExecutionWindow","description":"Time threshold between URL click and suspicious process execution."}],"live":true,"detection_strategies":["DET0107"],"techniques":["T1566.002"]},{"id":"AN0299","stix_id":"x-mitre-analytic--e08e4dd6-cab5-41c0-b136-1bc8426c25ed","name":"Analytic 0299","description":"Detection of spearphishing links through mail logs and browser activity. Behavior includes email with suspicious URLs → user click recorded in mail/web proxy logs → shell or interpreter launched from browser process.","url":"https://attack.mitre.org/detectionstrategies/DET0107#AN0299","platforms":["Linux"],"log_source_references":[{"name":"Application:Mail","channel":"Inbound emails containing hyperlinks from suspicious sources","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"application-mail"},{"name":"auditd:SYSCALL","channel":"execve: Execution of scripts or binaries spawned from browser processes","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Outbound requests to domains not previously resolved or associated with phishing campaigns","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MonitoredBrowsers","description":"List of browser processes to monitor (e.g., firefox, chrome, chromium)."},{"field":"PhishingIndicators","description":"Custom regex patterns for detecting obfuscated or IDN homograph URLs."}],"live":true,"detection_strategies":["DET0107"],"techniques":["T1566.002"]},{"id":"AN0300","stix_id":"x-mitre-analytic--b18b93d1-3f63-4788-8e26-68db032995e0","name":"Analytic 0300","description":"Correlation of Mail.app logs with Safari/Chrome activity. Suspicious behavior includes email links → Safari/Chrome accessing newly registered or lookalike domains → osascript or Terminal spawned unexpectedly.","url":"https://attack.mitre.org/detectionstrategies/DET0107#AN0300","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Received messages with embedded or shortened URLs","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Browser processes launching unexpected interpreters (osascript, bash)","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Connections to suspicious domains with mismatched certificate or unusual patterns","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"CertificateAnomalies","description":"Flag self-signed or mismatched TLS certificates from spearphishing domains."},{"field":"ExecutionDelayThreshold","description":"Suspicious delay between URL click and malicious process spawn."}],"live":true,"detection_strategies":["DET0107"],"techniques":["T1566.002"]},{"id":"AN0301","stix_id":"x-mitre-analytic--cfc7b6bc-2ca3-4407-a835-b40bf6a98efc","name":"Analytic 0301","description":"Detection of OAuth consent phishing or malicious login attempts initiated through spearphishing links. Behavior chain includes inbound email with OAuth URL → consent page visited → unusual token grants logged in IdP logs.","url":"https://attack.mitre.org/detectionstrategies/DET0107#AN0301","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"ConsentGrant: Suspicious consent grants to non-approved or unknown applications","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"AllowedApps","description":"Whitelisted apps permitted for OAuth consent grants."},{"field":"AnomalousConsentPatterns","description":"Patterns of consent from unusual geographies, devices, or unapproved applications."}],"live":true,"detection_strategies":["DET0107"],"techniques":["T1566.002"]}],"live":true,"version":"1.0","techniques":["T1566.002"]}],"sigma_rules":[{"id":"3569aefd-e535-4391-8c18-24bd01a21eaf","title":"Suspicious Email Delivered In Microsoft 365","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2026-01-27","modified":null,"description":"Detects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder.\nIt might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.\n","references":["https://learn.microsoft.com/en-us/defender-office-365/threat-explorer-real-time-detections-about","https://research.splunk.com/cloud/605cc93a-70e4-4ee3-9a3d-1a62e8c9b6c2/","https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules/blob/e7250648cb16d4a497ae8737943bf010ea96d2e6/Defender%20For%20Cloud%20Apps/MaliciousEmailDeliveredInMailbox.md"],"logsource":{"product":"m365","service":"audit"},"tags":["attack.initial-access","attack.t1566.001","attack.t1566.002"],"path":"rules/cloud/m365/audit/microsoft365_suspicious_email_delivered.yml","techniques":["T1566.001","T1566.002"],"cves":[]},{"id":"38e7f511-3f74-41d4-836e-f57dfa18eead","title":"Potential Malicious Usage of CloudTrail System Manager","author":"jamesc-grafana","status":"test","level":"high","date":"2024-07-11","modified":"2025-12-08","description":"Detect when System Manager successfully executes commands against an instance.\n","references":["https://github.com/elastic/detection-rules/blob/v8.6.0/rules/integrations/aws/initial_access_via_system_manager.toml"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.privilege-escalation","attack.initial-access","attack.t1566","attack.t1566.002"],"path":"rules/cloud/aws/cloudtrail/aws_cloudtrail_ssm_malicious_usage.yml","techniques":["T1566","T1566.002"],"cves":[]},{"id":"6e4dcdd1-e48b-42f7-b2d8-3b413fc58cb4","title":"Suspicious Execution via macOS Script Editor","author":"Tim Rauch (rule), Elastic (idea)","status":"test","level":"medium","date":"2022-10-21","modified":"2022-12-28","description":"Detects when the macOS Script Editor utility spawns an unusual child process.","references":["https://github.com/elastic/protections-artifacts/commit/746086721fd385d9f5c6647cada1788db4aea95f#diff-7f541fbc4a4a28a92970e8bf53effea5bd934604429112c920affb457f5b2685","https://wojciechregula.blog/post/macos-red-teaming-initial-access-via-applescript-url/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.defense-impairment","attack.t1566","attack.t1566.002","attack.initial-access","attack.t1059","attack.t1059.002","attack.t1204","attack.t1204.001","attack.execution","attack.persistence","attack.t1553"],"path":"rules/macos/process_creation/proc_creation_macos_susp_execution_macos_script_editor.yml","techniques":["T1566","T1566.002","T1059","T1059.002","T1204","T1204.001","T1553"],"cves":[]},{"id":"e0e121d0-be4d-4281-af7e-17abbba4a408","title":"EvilTokens PhaaS Kit Phishing Related Request - Proxy","author":"uniqu3-us3r","status":"experimental","level":"low","date":"2026-04-28","modified":null,"description":"Detects outbound web proxy requests to URLs matching the EvilTokens Phishing-as-a-Service (PhaaS) kit infrastructure.\nSpecifically Cloudflare Workers and Railway.app domains used in OAuth device code authorization phishing attacks.\nThis indicates a user has clicked a phishing link.\n","references":["https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.t1566.002","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/EvilTokens/proxy_eviltokens_cloudflare_worker_request.yml","techniques":["T1566.002"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-2533","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-42009","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-27443","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2024-21413","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2015-5119","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}