Phishing T1660

Mobile Tactic: Initial Access

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType1eq 1SMISHING_ALERT
SmishingAlertSeverity1in 1CRITICAL, HIGH
SmishingAlertType1in 1CREDENTIAL_HARVESTING, FRAUD_DETECTION, PHISHING_DETECTION

Top indicator values (6 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
SMISHING_ALERT
1
SmishingAlertSeverityin
CRITICAL
1
SmishingAlertSeverityin
HIGH
1
SmishingAlertTypein
CREDENTIAL_HARVESTING
1
SmishingAlertTypein
FRAUD_DETECTION
1
SmishingAlertTypein
PHISHING_DETECTION
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Application

Domain: Application

Kusto 1 rule