Cross-source coverage
T1566.001 / ATT&CK
Phishing: Spearphishing Attachment
From MITRE ATT&CK 19.2
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.
There are many options for the attachment such as Microsoft Office documents, executables, PDFs, or archived files. Upon opening the attachment (and potentially clicking past protections), the adversary's payload exploits a vulnerability or directly executes on the user's system. The text of the spearphishing email usually tries to give a plausible reason why the file should be opened, and may explain how to bypass system protections in order to do so. The email may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses. Adversaries frequently manipulate file extensions and icons in order to make attached executables appear to be document files, or files exploiting one application appear to be a file for a different one.
- Tactics
- Initial Access
- Platforms
- Linux · macOS · Windows
- Telemetry
-
m365:unifiedWinEventLog:SysmonApplication:Mailauditd:SYSCALLNSM:Flowmacos:unifiedlog
How MITRE says to detect it DET0236
Detection Strategy for Spearphishing Attachment across OS Platforms
Windows Analytic 0655
Detection of spearphishing attachments by correlating suspicious email delivery with subsequent file creation and abnormal process execution (e.g., Office spawning PowerShell or CMD). Behavior chain includes inbound email metadata → attachment stored on disk → process execution → outbound network activity.
m365:unifiedSend/Receive: Inbound emails with attachments from suspicious or spoofed sendersWinEventLog:SysmonEventCode=11WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=3, 22
Linux Analytic 0656
Phishing attachments executed on Linux systems are detected by linking email logs to file creation in mail directories and subsequent suspicious process execution. Look for unexpected binaries or scripts spawned from user mail directories and anomalous outbound network activity.
Application:MailInbound email attachments logged from MTAs with suspicious metadataauditd:SYSCALLexecve: Execution of files saved in mail or download directoriesNSM:FlowOutbound traffic from suspicious new processes post-attachment execution
macOS Analytic 0657
Phishing attachment detection on macOS through correlation of Mail app logs, file creation in user directories, and abnormal process execution (e.g., Preview.app or Mail.app spawning Terminal or scripting binaries). Network traffic after attachment interaction is also monitored.
macos:unifiedlogInbound messages with attachments from suspicious domainsmacos:unifiedlogExecution of Terminal, osascript, or other interpreters originating from Mail or Previewmacos:unifiedlogAttachment files written to ~/Downloads or temporary folders
elastic/protections-artifacts
69 rules| Detection | Severity | Format |
|---|---|---|
| Command Shell Execution from Untrusted Origin | Undefined | Elastic TOML |
| DLL Loaded from a Macro Enabled Document | Undefined | Elastic TOML |
| DLL Side Loading of a file dropped by Microsoft Office | Undefined | Elastic TOML |
| Embedded Executable via Windows Shortcut File | Undefined | Elastic TOML |
| Execution from a Downloaded ISO File | Undefined | Elastic TOML |
| Execution from a Macro Enabled Office Document | Undefined | Elastic TOML |
| Execution from a Remote Working Directory | Undefined | Elastic TOML |
| Execution of Commonly Abused Utilities via Explorer Trampoline | Undefined | Elastic TOML |
| Execution of File Written or Modified by Microsoft Equation Editor | Undefined | Elastic TOML |
| Execution of File Written or Modified by Microsoft Office | Undefined | Elastic TOML |
+ 59 more from elastic/protections-artifacts → showing the 10 highest-severity
splunk/security_content
32 rules| Detection | Severity | Format |
|---|---|---|
| Detect Outlook exe writing a zip file | Undefined | SPL |
| Email Attachments With Lots Of Spaces | Undefined | SPL |
| GSuite Email Suspicious Attachment | Undefined | SPL |
| Gsuite Email Suspicious Subject With Attachment | Undefined | SPL |
| Gsuite Email With Known Abuse Web Service Link | Undefined | SPL |
| Gsuite Suspicious Shared File Name | Undefined | SPL |
| O365 Email Reported By Admin Found Malicious | Undefined | SPL |
| O365 Email Reported By User Found Malicious | Undefined | SPL |
| O365 Safe Links Detection | Undefined | SPL |
| O365 Threat Intelligence Suspicious Email Delivered | Undefined | SPL |
+ 22 more from splunk/security_content → showing the 10 highest-severity
SigmaHQ/sigma
23 rules| Detection | Severity | Format |
|---|---|---|
| Droppers Exploiting CVE-2017-11882 | Critical | Sigma |
| Exploit for CVE-2017-8759 | Critical | Sigma |
| HTML Help HH.EXE Suspicious Child Process | High | Sigma |
| ISO File Created Within Temp Folders | High | Sigma |
| Office Macro File Creation From Suspicious Process | High | Sigma |
| Password Protected ZIP File Opened (Email Attachment) | High | Sigma |
| Suspicious Double Extension File Execution | High | Sigma |
| Suspicious Execution From Outlook Temporary Folder | High | Sigma |
| Suspicious File Created in Outlook Temporary Directory | High | Sigma |
| Suspicious HH.EXE Execution | High | Sigma |
+ 13 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
22 rules| Detection | Severity | Format |
|---|---|---|
| Execution of File Written or Modified by Microsoft Office | High | Elastic TOML |
| Potential CVE-2025-33053 Exploitation | High | Elastic TOML |
| Potential Execution via FileFix Phishing Attack | High | Elastic TOML |
| Potential Fake CAPTCHA Phishing Attack | High | Elastic TOML |
| Potential Foxmail Exploitation | High | Elastic TOML |
| Suspicious Execution from INET Cache | High | Elastic TOML |
| Unusual Execution via Microsoft Common Console File | High | Elastic TOML |
| Deprecated - M365 Security Compliance Email Reported by User as Malware or Phish | Medium | Elastic TOML |
| Downloaded Shortcut Files | Medium | Elastic TOML |
| Downloaded URL Files | Medium | Elastic TOML |
+ 12 more from elastic/detection-rules → showing the 10 highest-severity
Bert-JanP/Hunting-Queries-Detection-Rules
6 rules| Detection | Severity | Format |
|---|---|---|
| Anomalous Amount of URLClickEvents | Undefined | KQL |
| ASR Executable Content triggered | Undefined | KQL |
| AsyncRAT Initial Access Campaign via OneNote files | Undefined | KQL |
| Executable Fileattachment recieved | Undefined | KQL |
| Macro attachment opened from rare sender | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
chainguard-dev/osquery-defense-kit
5 rules · 4 families| Detection | Severity | Format |
|---|---|---|
| Look for sketchy mounted disk images, inspired by Shlayer 2 variants | Undefined | osquery SQL |
| Look for sketchy mounted disk images, inspired by Shlayer 2 variants | Undefined | osquery SQL |
| Scan removable volumes for sketchy files | Undefined | osquery SQL |
| Surface ISO/DMG disk images that were downloaded from unexpected places | Undefined | osquery SQL |
| Surface webmail downloads of an unexpected sort | Undefined | osquery SQL |
panther-labs/panther-analysis
4 rules| Detection | Severity | Format |
|---|---|---|
| Slack Potentially Malicious File Shared | Critical | Panther Python |
| Gmail Potential Spoofed Email Delivered | High | Panther Python |
| Gsuite Attachments Downloaded from Spam Email | High | Panther Python |
| Malware Detected in Email | High | Panther Python |