kevmap

TechniquesT1534 › AN0147

AN0147 Analytic 0147

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts.</p>
Detects
T1534 Internal Spearphishing
Part of
DET0054 Internal Spearphishing via Trusted Accounts

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4624, 4648DC0067 Logon Session Creation
WinEventLog:SecurityEventCode=4625DC0002 User Account Authentication
WinEventLog:SecurityEventCode=4672DC0088 Logon Session Metadata
m365:unifiedSendOnBehalf, MessageSend, ClickThrough, MailItemsAccessedDC0038 Application Log Content
WinEventLog:SysmonEventCode=1DC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TimeWindowExpected time between internal email and link execution or file dropper
UserContextBaseline logon locations and device usage for sender accounts
AttachmentEntropyThresholdEntropy value over which attachment is considered suspicious