Phishing: Spearphishing Link T1566.002
Tactic: Initial Access
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
Events covered
18 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 57 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (107 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (411 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (112 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 3 rules
- Potential Malicious Usage of CloudTrail System Manager
- Suspicious Email Delivered In Microsoft 365
- Suspicious Execution via macOS Script Editor
Elastic 35 rules
- Deprecated - M365 Security Compliance Email Reported by User as Malware or Phish
- Downloaded Shortcut Files
- Downloaded URL Files
- Entra ID Concurrent Sign-in with Suspicious Properties
- Entra ID Illicit Consent Grant via Registered Application
- Entra ID Kali365 Default User-Agent Detected
- Entra ID Microsoft Authentication Broker DRS Sign-In from Suspicious ASN
- Entra ID Microsoft Authentication Broker Sign-In with Non-Standard User Agent
- Entra ID OAuth Authorization Code Grant for Unusual User, App, and Resource
- Entra ID OAuth Device Code Flow with Concurrent Sign-ins
- Entra ID OAuth Device Code Grant by Microsoft Authentication Broker
- Entra ID OAuth Device Code Grant by Unusual User
- Entra ID OAuth Device Code Phishing via AiTM
- Entra ID OAuth Flow by Microsoft Authentication Broker to Device Registration Service (DRS)
- Entra ID OAuth Phishing via First-Party Microsoft Application
- Execution of File Written or Modified by Microsoft Office
- File with Suspicious Extension Downloaded
- Google Workspace Device Registration After OAuth from Suspicious ASN
- Google Workspace Object Copied to External Drive with App Consent
- M365 Identity OAuth Flow by First-Party Microsoft App from Multiple IPs
- M365 Identity OAuth Flow by User Sign-in to Device Registration
- M365 Identity OAuth Illicit Consent Grant by Rare Client and User
- M365 Identity OAuth Phishing via First-Party Microsoft Application
- M365 Quarantine and Hygiene Signal
- M365 Threat Intelligence Signal
- Network Traffic to Rare Destination Country
- Okta FastPass Phishing Detection
- Potential CVE-2025-33053 Exploitation
- Potential Execution via FileFix Phishing Attack
- Potential Remote File Execution via MSIEXEC
- Remote XSL Script Execution via COM
- Suspicious Explorer Child Process
- Suspicious HTML File Creation
- Unusual Execution via Microsoft Common Console File
- Unusual Network Destination Domain Name
Splunk 9 rules
- Azure AD Device Code Authentication
- O365 Email Reported By Admin Found Malicious
- O365 Email Reported By User Found Malicious
- O365 Threat Intelligence Suspicious Email Delivered
- O365 ZAP Activity Detection
- Process Creating LNK file in Suspicious Location
- Windows Defender ASR Audit Events
- Windows Defender ASR Block Events
- Windows Defender ASR Rules Stacking
Kusto 6 rules
- Acronis - Multiple Inboxes with Malicious Content Detected
- Detect external user sending suspicious link to multiple users
- Detect Malicious Teams Message
- Office ASR rule triggered from browser spawned office process.
- Suspicious parentprocess relationship - Office child processes.
- T1566.002 Spearphishing Link - Rare URL Clicks