{"id":"T1598.002","name":"Spearphishing Attachment","url":"https://attack.mitre.org/techniques/T1598/002","tactics":["reconnaissance"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0865","stix_id":"x-mitre-detection-strategy--e62ddd99-6357-4388-b3df-d7d7b6984630","name":"Detection of Spearphishing Attachment","url":"https://attack.mitre.org/detectionstrategies/DET0865","analytics":[{"id":"AN1997","stix_id":"x-mitre-analytic--705ecef8-b41e-4b1f-bd7c-f3b2ff930c11","name":"Analytic 1997","description":"Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.\nMonitor for suspicious email activity, such as numerous accounts receiving messages from a single unusual/unknown sender. Filtering based on DKIM+SPF or header analysis can help detect when the email sender is spoofed.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing)\nMonitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).","url":"https://attack.mitre.org/detectionstrategies/DET0865#AN1997","platforms":["PRE"],"log_source_references":[{"name":"Network Traffic","channel":"None","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"network-traffic"},{"name":"Application Log","channel":"None","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"application-log"},{"name":"Network Traffic","channel":"None","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"network-traffic"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0865"],"techniques":["T1598.002"]}],"live":true,"version":"1.0","techniques":["T1598.002"]}],"sigma_rules":[{"id":"538c5851-8c03-4724-8ec4-623bc7aadaea","title":"HTML File Opened From Download Folder","author":"Joseph Kamau","status":"experimental","level":"low","date":"2025-12-05","modified":null,"description":"Detects web browser process opening an HTML file from a user's Downloads folder.\nThis behavior is could be associated with phishing attacks where threat actors send HTML attachments to users.\nWhen a user opens such an attachment, it can lead to the execution of malicious scripts or the download of malware.\nDuring investigation, analyze the HTML file for embedded scripts or links, check for any subsequent downloads or process executions, and investigate the source of the email or message containing the attachment.\n","references":["https://app.any.run/tasks/ae3c4ded-fd6a-43ed-8215-ba0ba574ad33","https://app.any.run/tasks/8901e2d5-0c5a-48ba-a8e9-10b5ed7e06f4"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1598.002","attack.t1566.001","attack.initial-access","attack.reconnaissance","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_susp_open_html_file_from_download_folder.yml","techniques":["T1598.002","T1566.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2021-33739","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}