Phishing T1566

Tactic: Initial Access

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Events covered

50 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 7Image loaded
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 22DNSEvent (DNS query)
Security-AuditingEvent ID 4656A handle to an object was requested.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 5152The Windows Filtering Platform blocked a packet.
Security-AuditingEvent ID 5154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
Security-AuditingEvent ID 5155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Security-AuditingEvent ID 5157The Windows Filtering Platform has blocked a connection.
Security-AuditingEvent ID 5158The Windows Filtering Platform has permitted a bind to a local port.
Security-AuditingEvent ID 5159The Windows Filtering Platform has blocked a bind to a local port.
Security-AuditingEvent ID 5379Credential Manager credentials were read.
Defender-AlertEvidenceanyAlert evidence
Defender-CloudAppEventsanyCloud app activity
Defender-DeviceEventsanyDefender event
Defender-DeviceEventsBrowserLaunchedToOpenUrlBrowser launched to open URL
Defender-DeviceFileEventsanyFile activity
Defender-DeviceFileEventsFileCreatedFile created
Defender-DeviceFileEventsFileRenamedFile renamed
Defender-DeviceNetworkEventsanyNetwork activity
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceProcessEventsProcessCreatedProcess created
Defender-EmailEventsanyEmail processed
Defender-EmailUrlInfoanyEmail URL observed
Defender-IdentityInfoanyIdentity information
Defender-MessageEventsanyTeams message processed
Defender-MessageUrlInfoanyTeams message URL observed
Defender-UrlClickEventsanyURL click activity
ESFexecProcess Execution
ESFforkProcess Fork
ESFcreateFile or Directory Create
ESFwriteFile Write
Windows-DefenderEvent ID 1121Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
Windows-DefenderEvent ID 1122Microsoft Defender Exploit Guard audited an operation that is not allowed by your IT administrator.
Windows-DefenderEvent ID 1125Your IT administrator would have caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.
Windows-DefenderEvent ID 1126Your IT administrator has caused Microsoft Defender Exploit Guard to block a potentially dangerous network connection.
Windows-DefenderEvent ID 1129A user has allowed a blocked Microsoft Defender Exploit Guard operation.
Windows-DefenderEvent ID 1131ProductName has blocked an operation that your administrator doesn't allow.
Windows-DefenderEvent ID 1132ProductName has audited an operation.
Windows-DefenderEvent ID 1133ProductName has blocked an operation that your administrator doesn't allow.
Windows-DefenderEvent ID 1134ProductName has audited an operation.
Windows-DefenderEvent ID 5007Product Name Configuration has changed.
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 356 rules share fields, values, and exclusions.

Fields filtered most (372 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType103eq 89, ne 21, in 5, contains 2, starts_with 1start, deletion, creation, exec, modification
process_name92eq 80, in 13, wildcard 3, starts_with 1excel.exe, cmd.exe, cscript.exe, powerpnt.exe, eqnedt32.exe
parent_process_name64eq 51, in 11, regex_match 2, wildcard 1excel.exe, explorer.exe, eqnedt32.exe, powerpnt.exe, winword.exe
Image35ends_with 14, wildcard 9, contains 5, starts_with 5, is_not_null 4, eq 1, in 1, regex_match 1?:\users\*\appdata\local\microsoft\windows\inetcache\ie\*, ?:\users\*\downloads\*, \brave.exe, \certutil.exe, \chrome.exe
TargetFilename32wildcard 17, contains 9, ends_with 9, in 2, regex_match 2, match 1, starts_with 1?:\users\*\appdata\roaming\microsoft\windows\start..., .docm, .dotm, ?:\programdata\microsoft\windows\start menu\programs\startup\*, .iso
file.extension29eq 28, starts_with 1com, exe, bat, cmd, cpl
data_stream.dataset25eq 22, in 3azure.signinlogs, o365.audit, azure.activitylogs, google_workspace.token, azure.auditlogs
CommandLine24contains 15, wildcard 4, ends_with 2, regex_match 2, in 1, ne 1, starts_with 1(?i)((\x5cAppData\x5cLocal\x5cMicrosoft\x5cWindows\x5c.*\..., \downloads\, .exe, &, * -e *
event.type24eq 24, ne 1start, creation, change, deletion
host.os.type24eq 24
process.args24eq 13, wildcard 13, contains 4, starts_with 3, ends_with 2, regex_match 2, in 1--single-argument, -url, ., .cmd, .hta
sourcetype24eq 24zscalernss-web, o365:management:activity, gsuite:gmail:bigquery, gws:reports:drive, azure:monitor:aad
ParentImage22ends_with 9, eq 8, in 2, is_not_null 2, starts_with 1?:\windows\hh.exe, ?:\windows\system32\mmc.exe, \winword.exe, c:\program files\internet explorer\iediagcmd.exe, */ghostscript
OriginalFileName21eq 16, in 5cmd.exe, cscript.exe, bitsadmin.exe, certutil.exe, mshta.exe
EventID19eq 13, in 61, 7, 1121, 1122, 1125

Top indicator values (2322 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
start
60391
process_nameeq
excel.exe
2434
process_nameeq
winword.exe
2435
process_nameeq
powerpnt.exe
2331
process_nameeq
powershell.exe
23184
process_nameeq
mshta.exe
1984
process_nameeq
cmd.exe
18121
process_nameeq
wscript.exe
1883
process_nameeq
cscript.exe
1567
process_nameeq
msaccess.exe
1519
process_nameeq
rundll32.exe
12126
process_nameeq
mspub.exe
1115
process_nameeq
certutil.exe
1044
process_nameeq
regsvr32.exe
1073
EventTypene
deletion
2186
event.typeeq
start
191078
parent_process_nameeq
excel.exe
1628
parent_process_nameeq
winword.exe
1626
parent_process_nameeq
explorer.exe
1551
parent_process_nameeq
powerpnt.exe
1523
file.Ext.header_bytesstarts_with
4d5a
1346
Activeeq
true
1270
file.extensioneq
exe
1232
sourcetypeeq
zscalernss-web
1212
event.outcomeeq
success
11369
OriginalFileNameeq
mshta.exe
1040
OriginalFileNameeq
cscript.exe
932
OriginalFileNameeq
rundll32.exe
978
data_stream.dataseteq
azure.signinlogs
1036
NetworkDirectioneq
incoming
99

Exclusions (965 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
16
process_nameeq
rundll32.exe
15
process_nameeq
cmd.exe
8
process_nameeq
powershell.exe
8
process_nameeq
wscript.exe
7
Imagewildcard
?:\program files\*.exe
9
Imagewildcard
?:\program files (x86)\*.exe
8
Imagewildcard
?:\windows\system32\werfault.exe
6
Imagewildcard
?:\windows\system32\dwwin.exe
4
Imagewildcard
?:\windows\syswow64\werfault.exe
4
DeliveryActioncontains
blocked
6
Descriptioncontains
State: falsepos;
6
Descriptioncontains
State: inactive;
6
process.Ext.token.integrity_level_nameeq
system
6
process.argswildcard
ndfapi.dll,NdfRunDllDiagnoseWithAnswerFile
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 36 rules

Elastic 136 rules

Splunk 57 rules

Kusto 99 rules

YARA-L 4 rules

Panther 24 rules