1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1566.003 Spearphishing via Service — Detection Rules

Detection workspace for T1566.003 Spearphishing via Service: 0 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

T1566.003 Spearphishing via Service

MATCH(external_message_contains_url_or_attachment) AND sender NOT_IN approved_external_senders -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0115 Detection Strategy for Spearphishing via a Service across OS Platforms

AN0320 Analytic 0320

Inbound spearphishing attempts delivered via third-party services (e.g., Gmail, LinkedIn messages) leading to malicious file downloads or browser-initiated script execution. Defender view includes correlation of external service logins, unexpected file write operations, and suspicious descendant processes spawned from productivity or browser applications.

AN0321 Analytic 0321

Use of non-enterprise email or messaging services in Thunderbird, Evolution, or browsers leading to suspicious file downloads and subsequent execution. Defender view includes browser-initiated downloads of unexpected content and shell or interpreter processes launched post-download.

AN0322 Analytic 0322

Phishing attempts via iCloud Mail, Gmail, or social media apps accessed on macOS systems. Defender view includes Mail.app or Safari downloads of files followed by osascript, Terminal, or abnormal child process execution.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1566.003 simulation workspace

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.