kevmap

TechniquesT1566.002 › AN0300

AN0300 Analytic 0300

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Correlation of Mail.app logs with Safari/Chrome activity. Suspicious behavior includes email links → Safari/Chrome accessing newly registered or lookalike domains → osascript or Terminal spawned unexpectedly.</p>
Detects
T1566.002 Spearphishing Link
Part of
DET0107 Detection Strategy for Spearphishing Links

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogReceived messages with embedded or shortened URLsDC0038 Application Log Content
macos:unifiedlogBrowser processes launching unexpected interpreters (osascript, bash)DC0032 Process Creation
macos:unifiedlogConnections to suspicious domains with mismatched certificate or unusual patternsDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
CertificateAnomaliesFlag self-signed or mismatched TLS certificates from spearphishing domains.
ExecutionDelayThresholdSuspicious delay between URL click and malicious process spawn.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2015-5119Adobe Flash PlayerMapped
CVE-2023-2533PaperCut NG/MFMapped
CVE-2024-21413Microsoft Office OutlookMapped
CVE-2024-27443Synacor Zimbra Collaboration Suite (ZCS)Mapped
CVE-2024-42009Roundcube WebmailMapped