1200KM / detection
T0865 Spearphishing Attachment — Detection Rules
Detection workspace for T0865 Spearphishing Attachment: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0781 Detection of Spearphishing Attachment
AN1913 Analytic 1913
Monitor for suspicious descendant process spawning from Microsoft Office and other productivity software. For added context on adversary procedures and background see Spearphishing Attachment. Monitor for newly constructed files from a spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Monitor network traffic for suspicious email attachments. Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g., monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)). Use web proxies to review content of emails including sender information, headers, and attachments for potentially malicious content. Monitor mail server and proxy logs for evidence of messages originating from spoofed addresses, including records indicating failed DKIM+SPF validation or mismatched message headers. Anti-virus can potentially detect malicious documents and attachments as they're scanned to be stored on the email server or on the user's computer.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Application Log Content · DC0038
- File Creation · DC0039
- Network Traffic Content · DC0085
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.