1200KM / detection
T1566.002 Spearphishing Link — Detection Rules
Detection workspace for T1566.002 Spearphishing Link: 3 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Potential Malicious Usage of CloudTrail System Manager · test · high · {"product":"aws","service":"cloudtrail"}
- Suspicious Email Delivered In Microsoft 365 · experimental · medium · {"service":"audit","product":"m365"}
- Suspicious Execution via macOS Script Editor · test · medium · {"category":"process_creation","product":"macos"}
Atlas deterministic concepts
T1566.002 Spearphishing Link
MATCH(message_url IN denylist OR url_category = malicious) -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0107 Detection Strategy for Spearphishing Links
AN0298 Analytic 0298
Correlation of inbound emails with embedded links followed by user-driven browser navigation to suspicious or obfuscated domains. Detection chain includes malicious URL in email → user click recorded in Office logs → browser process spawning unusual child processes (e.g., PowerShell, cmd) or download activity.
AN0299 Analytic 0299
Detection of spearphishing links through mail logs and browser activity. Behavior includes email with suspicious URLs → user click recorded in mail/web proxy logs → shell or interpreter launched from browser process.
AN0300 Analytic 0300
Correlation of Mail.app logs with Safari/Chrome activity. Suspicious behavior includes email links → Safari/Chrome accessing newly registered or lookalike domains → osascript or Terminal spawned unexpectedly.
AN0301 Analytic 0301
Detection of OAuth consent phishing or malicious login attempts initiated through spearphishing links. Behavior chain includes inbound email with OAuth URL → consent page visited → unusual token grants logged in IdP logs.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT1 · G0006
- Turla · G0010
- APT29 · G0016
- Molerats · G0021
- APT3 · G0022
- Lazarus Group · G0032
- Sandworm Team · G0034
- Patchwork · G0040
- FIN7 · G0046
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- FIN8 · G0061
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- MuddyWater · G0069
- Cobalt Group · G0080
- FIN4 · G0085
- APT39 · G0087
- WIRTE · G0090
- TA505 · G0092
- Kimsuky · G0094
- Machete · G0095
- BlackTech · G0098
- APT-C-36 · G0099
- Wizard Spider · G0102
- Mofang · G0103
- Windshift · G0112
- Evilnum · G0120
- Sidewinder · G0121
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- Transparent Tribe · G0134
- LazyScripter · G0140
- Confucius · G0142
- Earth Lusca · G1006
- EXOTIC LILY · G1011
- LuminousMoth · G1014
- TA2541 · G1018
- Mustard Tempest · G1020
- TA577 · G1037
- RedCurl · G1039
- APT42 · G1044
- Storm-1811 · G1046
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.