kevmap

TechniquesT1566.004 › AN0686

AN0686 Analytic 0686

Identity Provider · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Correlate MFA push fatigue or unusual consent grant attempts with call activity where adversaries may have socially engineered the user over voice.</p>
Detects
T1566.004 Spearphishing Voice
Part of
DET0245 Detection Strategy for Spearphishing Voice across OS platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
m365:unifiedUnusual MFA requests or OAuth consent events temporally aligned with user-reported vishing callDC0038 Application Log Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
MFARequestThresholdNumber of MFA push requests within a timeframe aligned to a suspicious call
ConsentGrantPatternsUnusual OAuth consent URLs or delegated scopes