Techniques › T1534 › AN0148
AN0148 Analytic 0148
Linux · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Delivery of suspicious internal communication (e.g., Thunderbird, Evolution) using compromised internal accounts. Sequence of: unexpected user activity + mail transfer logs + download or execution of attachments.</p>
- Detects
- T1534 Internal Spearphishing
- Part of
- DET0054 Internal Spearphishing via Trusted Accounts
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| auditd:SYSCALL | execve | DC0032 Process Creation |
| Application:Mail | smtpd$.*$: .*from=[.*@internaldomain.com](mailto:.*@internaldomain.com) to=[.*@internaldomain.com](mailto:.*@internaldomain.com) | DC0038 Application Log Content |
| linux:syslog | curl|wget|python .*http | DC0085 Network Traffic Content |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
SubjectLineAnomaly | Deviation from typical internal email subjects |
AttachmentType | Executable types allowed or flagged by mail relay |