MITRE ATT&CK technique
Phishing detection rulesT1566
Phishing (T1566) is a MITRE ATT&CK technique in the Initial Access tactic. This page lists the 35 community-maintained Sigma detection rules in the library mapped to T1566 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, macos, okta.
CVE-2021-31979 CVE-2021-33771 Exploits
criticalDetects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
windows · registry_set
CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum
criticalDetects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
windows · file_event
Droppers Exploiting CVE-2017-11882
criticalDetects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
windows · process_creation
Exploit for CVE-2017-8759
criticalDetects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759
windows · process_creation
Ursnif Malware C2 URL Pattern
criticalDetects Ursnif C2 traffic.
proxy
HTML Help HH.EXE Suspicious Child Process
highDetects a suspicious child process of a Microsoft HTML Help (HH.exe)
windows · process_creation
ISO File Created Within Temp Folders
highDetects the creation of a ISO file in the Outlook temp folder or in the Appdata temp folder. Typical of Qakbot TTP from end-July 2022.
windows · file_event
Office Macro File Creation From Suspicious Process
highDetects the creation of a office macro file from a a suspicious process
windows · file_event
Okta FastPass Phishing Detection
highDetects when Okta FastPass prevents a known phishing site.
okta
Password Protected ZIP File Opened (Email Attachment)
highDetects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.
windows
Phishing Pattern ISO in Archive
highDetects cases in which an ISO files is opend within an archiver like 7Zip or Winrar, which is a sign of phishing as threat actors put small ISO files in archives as email attachments to bypass certain filters and protective measures (mark of web)
windows · process_creation
Potential Malicious Usage of CloudTrail System Manager
highDetect when System Manager successfully executes commands against an instance.
aws
Suspicious Double Extension File Execution
highDetects suspicious use of an .exe extension after a non-executable file extension like .pdf.exe, a set of spaces or underlines to cloak the executable file in spear phishing campaigns
windows · process_creation
Suspicious Execution From Outlook Temporary Folder
highDetects a suspicious program execution in Outlook temp folder
windows · process_creation
Suspicious External WebDAV Execution
highDetects executables launched from external WebDAV shares using the WebDAV Explorer integration, commonly seen in initial access campaigns.
proxy
Suspicious File Created in Outlook Temporary Directory
highDetects the creation of files with suspicious file extensions in the temporary directory that Outlook uses when opening attachments. This can be used to detect spear-phishing campaigns that use suspicious files as attachments, which may contain malicious code.
windows · file_event
Suspicious HH.EXE Execution
highDetects a suspicious execution of a Microsoft HTML Help (HH.exe)
windows · process_creation
Suspicious HWP Sub Processes
highDetects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation
windows · process_creation
Suspicious Microsoft OneNote Child Process
highDetects suspicious child processes of the Microsoft OneNote application. This may indicate an attempt to execute malicious embedded objects from a .one file.
windows · process_creation
Arbitrary Shell Command Execution Via Settingcontent-Ms
mediumThe .SettingContent-ms file type was introduced in Windows 10 and allows a user to create "shortcuts" to various Windows 10 setting pages. These files are simply XML and contain paths to various Windows 10 settings binaries.
windows · process_creation
Disk Image Mounting Via Hdiutil - MacOS
mediumDetects the execution of the hdiutil utility in order to mount disk images.
macos · process_creation
Exploit for CVE-2017-0261
mediumDetects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262
windows · process_creation
ISO Image Mounted
mediumDetects the mount of an ISO image on an endpoint
windows
ISO or Image Mount Indicator in Recent Files
mediumDetects the creation of recent element file that points to an .ISO, .IMG, .VHD or .VHDX file as often used in phishing attacks. This can be a false positive on server systems but on workstations users should rarely mount .iso or .img files.
windows · file_event
Potential Initial Access via DLL Search Order Hijacking
mediumDetects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.
windows · file_event
Suspicious Email Delivered In Microsoft 365
mediumDetects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder. It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.
m365
Suspicious Execution via macOS Script Editor
mediumDetects when the macOS Script Editor utility spawns an unusual child process.
macos · process_creation
WebDAV Temporary Local File Creation
mediumDetects the creation of WebDAV temporary files with potentially suspicious extensions
windows · file_event
Windows Registry Trust Record Modification
mediumAlerts on trust record modification within the registry, indicating usage of macros
windows · registry_event
Download From Suspicious TLD - Blacklist
lowDetects download of certain file types from hosts in suspicious TLDs
proxy
Download From Suspicious TLD - Whitelist
lowDetects executable downloads from suspicious remote systems
proxy
EvilTokens PhaaS Kit Phishing Related Request - Proxy
lowDetects outbound web proxy requests to URLs matching the EvilTokens Phishing-as-a-Service (PhaaS) kit infrastructure. Specifically Cloudflare Workers and Railway.app domains used in OAuth device code authorization phishing attacks. This indicates a user has clicked a phishing link.
proxy
HTML File Opened From Download Folder
lowDetects web browser process opening an HTML file from a user's Downloads folder. This behavior is could be associated with phishing attacks where threat actors send HTML attachments to users. When a user opens such an attachment, it can lead to the execution of malicious scripts or the download of malware. During investigation, analyze the HTML file for embedded scripts or links, check for any subsequent downloads or process executions, and investigate the source of the email or message containing the attachment.
windows · process_creation
Office Macro File Creation
lowDetects the creation of a new office macro files on the systems
windows · file_event
Office Macro File Download
lowDetects the creation of a new office macro files on the system via an application (browser, mail client). This can help identify potential malicious activity, such as the download of macro-enabled documents that could be used for exploitation.
windows · file_event