{"id":"T1566.004","name":"Spearphishing Voice","url":"https://attack.mitre.org/techniques/T1566/004","tactics":["initial-access"],"platforms":["Linux","macOS","Windows","Identity Provider"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0245","stix_id":"x-mitre-detection-strategy--ec33e12c-e0f1-426d-a453-fa5ae4d3cf9a","name":"Detection Strategy for Spearphishing Voice across OS platforms","url":"https://attack.mitre.org/detectionstrategies/DET0245","analytics":[{"id":"AN0683","stix_id":"x-mitre-analytic--caa11058-4906-48b4-ab3f-a650aab6968d","name":"Analytic 0683","description":"Monitor call log records from corporate devices for unusual or unauthorized numbers, especially repeated calls to/from known malicious phone numbers. Correlate with subsequent system events (e.g., browser navigation, remote management tool execution).","url":"https://attack.mitre.org/detectionstrategies/DET0245#AN0683","platforms":["Windows"],"log_source_references":[{"name":"ApplicationLog:CallRecords","channel":"Outbound or inbound calls to high-risk or blocklisted numbers","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"applicationlog-callrecords"}],"mutable_elements":[{"field":"PhoneNumberBlocklist","description":"List of known malicious or suspicious phone numbers; must be tuned per environment"},{"field":"TimeWindow","description":"Threshold for correlating call events with subsequent suspicious system activity"}],"live":true,"detection_strategies":["DET0245"],"techniques":["T1566.004"]},{"id":"AN0684","stix_id":"x-mitre-analytic--c5134555-561a-4905-8601-a6ba307fc121","name":"Analytic 0684","description":"Audit VoIP/SIP logs for suspicious outbound calls or call setup messages to unusual endpoints. Correlate with user activity such as browser execution or package installation following the call.","url":"https://attack.mitre.org/detectionstrategies/DET0245#AN0684","platforms":["Linux"],"log_source_references":[{"name":"networkdevice:syslog","channel":"SIP REGISTER, INVITE, or unusual call destination metadata","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"CallDestinationPatterns","description":"Regular expressions or rules for spotting abnormal call destinations"},{"field":"UserContext","description":"Expected users who initiate VoIP traffic vs. anomalous accounts"}],"live":true,"detection_strategies":["DET0245"],"techniques":["T1566.004"]},{"id":"AN0685","stix_id":"x-mitre-analytic--756214e0-660d-4f32-a4f1-f8ff24a7852f","name":"Analytic 0685","description":"Monitor Facetime, iMessage, or SIP client logs for anomalous voice call attempts. Link to subsequent user execution events (downloads, RMM installs) triggered post-call.","url":"https://attack.mitre.org/detectionstrategies/DET0245#AN0685","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Outgoing or incoming calls with non-standard caller IDs or unusual metadata","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"CallerIDPatterns","description":"Patterns of spoofed caller IDs that must be tuned based on region and telecom provider"},{"field":"PayloadCorrelation","description":"Define what follow-on events (browser downloads, execution) to correlate with call logs"}],"live":true,"detection_strategies":["DET0245"],"techniques":["T1566.004"]},{"id":"AN0686","stix_id":"x-mitre-analytic--345af006-d658-4f22-aef6-b1cfc0058875","name":"Analytic 0686","description":"Correlate MFA push fatigue or unusual consent grant attempts with call activity where adversaries may have socially engineered the user over voice.","url":"https://attack.mitre.org/detectionstrategies/DET0245#AN0686","platforms":["Identity Provider"],"log_source_references":[{"name":"m365:unified","channel":"Unusual MFA requests or OAuth consent events temporally aligned with user-reported vishing call","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"MFARequestThreshold","description":"Number of MFA push requests within a timeframe aligned to a suspicious call"},{"field":"ConsentGrantPatterns","description":"Unusual OAuth consent URLs or delegated scopes"}],"live":true,"detection_strategies":["DET0245"],"techniques":["T1566.004"]}],"live":true,"version":"1.0","techniques":["T1566.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}