Cross-source coverage

T1566.001 / ATT&CK

Phishing: Spearphishing Attachment

162 rules · 156 families across 7 sources.

2 deprecated hidden · include

Showing atomic-IOC rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

There are many options for the attachment such as Microsoft Office documents, executables, PDFs, or archived files. Upon opening the attachment (and potentially clicking past protections), the adversary's payload exploits a vulnerability or directly executes on the user's system. The text of the spearphishing email usually tries to give a plausible reason why the file should be opened, and may explain how to bypass system protections in order to do so. The email may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses. Adversaries frequently manipulate file extensions and icons in order to make attached executables appear to be document files, or files exploiting one application appear to be a file for a different one.

Tactics
Initial Access
Platforms
Linux · macOS · Windows
Telemetry
m365:unifiedWinEventLog:SysmonApplication:Mailauditd:SYSCALLNSM:Flowmacos:unifiedlog

How MITRE says to detect it DET0236

Detection Strategy for Spearphishing Attachment across OS Platforms

Windows Analytic 0655

Detection of spearphishing attachments by correlating suspicious email delivery with subsequent file creation and abnormal process execution (e.g., Office spawning PowerShell or CMD). Behavior chain includes inbound email metadata → attachment stored on disk → process execution → outbound network activity.

  • m365:unified Send/Receive: Inbound emails with attachments from suspicious or spoofed senders
  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=3, 22

Linux Analytic 0656

Phishing attachments executed on Linux systems are detected by linking email logs to file creation in mail directories and subsequent suspicious process execution. Look for unexpected binaries or scripts spawned from user mail directories and anomalous outbound network activity.

  • Application:Mail Inbound email attachments logged from MTAs with suspicious metadata
  • auditd:SYSCALL execve: Execution of files saved in mail or download directories
  • NSM:Flow Outbound traffic from suspicious new processes post-attachment execution

macOS Analytic 0657

Phishing attachment detection on macOS through correlation of Mail app logs, file creation in user directories, and abnormal process execution (e.g., Preview.app or Mail.app spawning Terminal or scripting binaries). Network traffic after attachment interaction is also monitored.

  • macos:unifiedlog Inbound messages with attachments from suspicious domains
  • macos:unifiedlog Execution of Terminal, osascript, or other interpreters originating from Mail or Preview
  • macos:unifiedlog Attachment files written to ~/Downloads or temporary folders

elastic/protections-artifacts

69 rules
Detection Severity Format
Command Shell Execution from Untrusted Origin Undefined Elastic TOML
DLL Loaded from a Macro Enabled Document Undefined Elastic TOML
DLL Side Loading of a file dropped by Microsoft Office Undefined Elastic TOML
Embedded Executable via Windows Shortcut File Undefined Elastic TOML
Execution from a Downloaded ISO File Undefined Elastic TOML
Execution from a Macro Enabled Office Document Undefined Elastic TOML
Execution from a Remote Working Directory Undefined Elastic TOML
Execution of Commonly Abused Utilities via Explorer Trampoline Undefined Elastic TOML
Execution of File Written or Modified by Microsoft Equation Editor Undefined Elastic TOML
Execution of File Written or Modified by Microsoft Office Undefined Elastic TOML

+ 59 more from elastic/protections-artifacts → showing the 10 highest-severity

splunk/security_content

32 rules
Detection Severity Format
Detect Outlook exe writing a zip file Undefined SPL
Email Attachments With Lots Of Spaces Undefined SPL
GSuite Email Suspicious Attachment Undefined SPL
Gsuite Email Suspicious Subject With Attachment Undefined SPL
Gsuite Email With Known Abuse Web Service Link Undefined SPL
Gsuite Suspicious Shared File Name Undefined SPL
O365 Email Reported By Admin Found Malicious Undefined SPL
O365 Email Reported By User Found Malicious Undefined SPL
O365 Safe Links Detection Undefined SPL
O365 Threat Intelligence Suspicious Email Delivered Undefined SPL

+ 22 more from splunk/security_content → showing the 10 highest-severity

SigmaHQ/sigma

24 rules
Detection Severity Format
Droppers Exploiting CVE-2017-11882 Critical Sigma
Exploit for CVE-2017-8759 Critical Sigma
Ursnif Malware C2 URL Pattern Critical Sigma
HTML Help HH.EXE Suspicious Child Process High Sigma
ISO File Created Within Temp Folders High Sigma
Office Macro File Creation From Suspicious Process High Sigma
Password Protected ZIP File Opened (Email Attachment) High Sigma
Suspicious Double Extension File Execution High Sigma
Suspicious Execution From Outlook Temporary Folder High Sigma
Suspicious File Created in Outlook Temporary Directory High Sigma

+ 14 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

22 rules
Detection Severity Format
Execution of File Written or Modified by Microsoft Office High Elastic TOML
Potential CVE-2025-33053 Exploitation High Elastic TOML
Potential Execution via FileFix Phishing Attack High Elastic TOML
Potential Fake CAPTCHA Phishing Attack High Elastic TOML
Potential Foxmail Exploitation High Elastic TOML
Suspicious Execution from INET Cache High Elastic TOML
Unusual Execution via Microsoft Common Console File High Elastic TOML
Deprecated - M365 Security Compliance Email Reported by User as Malware or Phish Medium Elastic TOML
Downloaded Shortcut Files Medium Elastic TOML
Downloaded URL Files Medium Elastic TOML

+ 12 more from elastic/detection-rules → showing the 10 highest-severity

Bert-JanP/Hunting-Queries-Detection-Rules

6 rules
Detection Severity Format
Anomalous Amount of URLClickEvents Undefined KQL
ASR Executable Content triggered Undefined KQL
AsyncRAT Initial Access Campaign via OneNote files Undefined KQL
Executable Fileattachment recieved Undefined KQL
Macro attachment opened from rare sender Undefined KQL
MITRE ATT&CK Mapping Undefined KQL

chainguard-dev/osquery-defense-kit

5 rules · 4 families
Detection Severity Format
Look for sketchy mounted disk images, inspired by Shlayer 2 variants Undefined osquery SQL
Look for sketchy mounted disk images, inspired by Shlayer 2 variants Undefined osquery SQL
Scan removable volumes for sketchy files Undefined osquery SQL
Surface ISO/DMG disk images that were downloaded from unexpected places Undefined osquery SQL
Surface webmail downloads of an unexpected sort Undefined osquery SQL

panther-labs/panther-analysis

4 rules
Detection Severity Format
Slack Potentially Malicious File Shared Critical Panther Python
Gmail Potential Spoofed Email Delivered High Panther Python
Gsuite Attachments Downloaded from Spam Email High Panther Python
Malware Detected in Email High Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.