Techniques › T1566 › T1566.001
T1566.001 Spearphishing Attachment
initial access — Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
24
Sigma rules tagged attack.t1566.001
7
KEV CVEs mapped here
<p>Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment is different from other forms of spearphishing in that it employs the use of malware attached to an email. All forms of spearphishing are electronically delivered social engineering targeted at a specific individual, company, or industry. In this scenario, adversaries attach a file to the spearphishing email and usually rely upon User Execution to gain execution. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.</p><p>There are many options for the attachment such as Microsoft Office documents, executables, PDFs, or archived files. Upon opening the attachment (and potentially clicking past protections), the adversary's payload exploits a vulnerability or directly executes on the user's system. The text of the spearphishing email usually tries to give a plausible reason why the file should be opened, and may explain how to bypass system protections in order to do so. The email may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses. Adversaries frequently manipulate file extensions and icons in order to make attached executables appear to be document files, or files exploiting one application appear to be a file for a different one.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-33053 | Microsoft Windows | exploitation technique | Mapped | 2025-06-10 |
| CVE-2025-0411 | 7-Zip 7-Zip | exploitation technique | Mapped | 2025-02-06 |
| CVE-2023-2868 | Barracuda Networks Email Security Gateway (ESG) Appliance | exploitation technique | Mapped | 2023-05-26 |
| CVE-2022-41033 | Microsoft Windows COM+ Event System Service | exploitation technique | Mapped | 2022-10-11 |
| CVE-2017-11292 | Adobe Flash Player | exploitation technique | Mapped | 2022-03-03 |
| CVE-2013-0640 | Adobe Reader and Acrobat | exploitation technique | Mapped | 2022-03-03 |
| CVE-2017-11882 | Microsoft Office | exploitation technique | Mapped | 2021-11-03 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0236 Detection Strategy for Spearphishing Attachment across OS Platforms v1.0
AN0655 WindowsDetection of spearphishing attachments by correlating suspicious email delivery with subsequent file creation and abnormal process execution (e.g., Office spawning PowerShell or CMD). Behavior chain includes inbound email metadata → attachment stored on disk → process execution → outbound network activity.m365:unified
Send/Receive: Inbound emails with attachments from suspicious or spoofed senders→ DC0038 Application Log ContentTunable:AttachmentExtensionsSuspiciousParentChildPairsTimeWindowAN0656 LinuxPhishing attachments executed on Linux systems are detected by linking email logs to file creation in mail directories and subsequent suspicious process execution. Look for unexpected binaries or scripts spawned from user mail directories and anomalous outbound network activity.Application:MailInbound email attachments logged from MTAs with suspicious metadata→ DC0038 Application Log Contentauditd:SYSCALLexecve: Execution of files saved in mail or download directories→ DC0032 Process CreationNSM:FlowOutbound traffic from suspicious new processes post-attachment execution→ DC0078 Network Traffic FlowTunable:AttachmentStoragePathsScriptInterpretersAN0657 macOSPhishing attachment detection on macOS through correlation of Mail app logs, file creation in user directories, and abnormal process execution (e.g., Preview.app or Mail.app spawning Terminal or scripting binaries). Network traffic after attachment interaction is also monitored.macos:unifiedlogInbound messages with attachments from suspicious domains→ DC0038 Application Log Contentmacos:unifiedlogExecution of Terminal, osascript, or other interpreters originating from Mail or Preview→ DC0032 Process Creationmacos:unifiedlogAttachment files written to ~/Downloads or temporary folders→ DC0039 File CreationTunable:ExecutionDelayThresholdSuspiciousParentApps
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1566.001
Author: Florian Roth (Nextron Systems)
· 2019-10-24 (modified 2021-11-27) · logsource: product=windows category=process_creation · 023394c4-29d5-46ab-92b8-6a534c6f447b
Detects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation
Author: Syed Hasan (@syedhasan009)
· 2021-05-29 (modified 2023-11-09) · logsource: product=windows service=security · 0248a7bc-8a9a-4cd8-a57e-3ae8e073a073
Detects the mount of an ISO image on an endpoint
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-01-23 (modified 2025-10-29) · logsource: product=windows category=file_event · 0e29e3a7-1ad8-40aa-b691-9f82ecd33d66
Detects the creation of a new office macro files on the system via an application (browser, mail client).
This can help identify potential malicious activity, such as the download of macro-enabled documents that could be used for exploitation.
Author: Florian Roth (Nextron Systems), @blu3_team (idea), Nasreddine Bencherchali (Nextron Systems)
· 2019-06-26 (modified 2025-05-30) · logsource: product=windows category=process_creation · 1cdd9a09-06c9-4769-99ff-626e2b3991b8
Detects suspicious use of an .exe extension after a non-executable file extension like .pdf.exe, a set of spaces or underlines to cloak the executable file in spear phishing campaigns
Author: Sreeman
· 2020-03-13 (modified 2022-04-14) · logsource: product=windows category=process_creation · 24de4f3b-804c-4165-b442-5a06a2302c7e
The .SettingContent-ms file type was introduced in Windows 10 and allows a user to create "shortcuts" to various Windows 10 setting pages. These files are simply XML and contain paths to various Windows 10 settings binaries.
Author: Antonlovesdnb, Trent Liffick (@tliffick)
· 2020-02-19 (modified 2023-06-21) · logsource: product=windows category=registry_event · 295a59c1-7b79-4b47-a930-df12c15fc9c2
Alerts on trust record modification within the registry, indicating usage of macros
Author: @sam0x90
· 2022-07-30 · logsource: product=windows category=file_event · 2f9356ae-bf43-41b8-b858-4496d83b2acb
Detects the creation of a ISO file in the Outlook temp folder or in the Appdata temp folder. Typical of Qakbot TTP from end-July 2022.
Author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
· 2026-01-27 · logsource: product=m365 service=audit · 3569aefd-e535-4391-8c18-24bd01a21eaf
Detects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder.
It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.
Author: Florian Roth (Nextron Systems)
· 2022-02-11 · logsource: product=windows category=file_event · 4358e5a5-7542-4dcb-b9f3-87667371839b
Detects the creation of recent element file that points to an .ISO, .IMG, .VHD or .VHDX file as often used in phishing attacks.
This can be a false positive on server systems but on workstations users should rarely mount .iso or .img files.
Author: Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems)
· 2020-04-01 (modified 2023-04-12) · logsource: product=windows category=process_creation · 52cad028-0ff0-4854-8f67-d25dfcbc78b4
Detects a suspicious child process of a Microsoft HTML Help (HH.exe)
Author: Joseph Kamau
· 2025-12-05 · logsource: product=windows category=process_creation · 538c5851-8c03-4724-8ec4-623bc7aadaea
Detects web browser process opening an HTML file from a user's Downloads folder.
This behavior is could be associated with phishing attacks where threat actors send HTML attachments to users.
When a user opens such an attachment, it can lead to the execution of malicious scripts or the download of malware.
During investigation, analyze the HTML file for embedded scripts or links, check for any subsequent downloads or process executions, and investigate the source of the email or message containing the attachment.
Author: Florian Roth (Nextron Systems)
· 2022-05-09 · logsource: product=windows service=security · 571498c8-908e-40b4-910b-d2369159a3da
Detects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.
Author: Florian Roth (Nextron Systems)
· 2017-11-23 (modified 2021-11-27) · logsource: product=windows category=process_creation · 678eb5f4-8597-4be6-8be7-905e4234b53a
Detects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
Author: Florian Roth (Nextron Systems)
· 2018-02-22 (modified 2021-11-27) · logsource: product=windows category=process_creation · 864403a1-36c9-40a2-a982-4c9a45f7d833
Detects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-01-23 (modified 2026-01-09) · logsource: product=windows category=file_event · 91174a41-dc8f-401b-be89-7bfc140612a0
Detects the creation of a new office macro files on the systems
Author: Thomas Patzke
· 2019-12-19 (modified 2021-08-09) · logsource: category=proxy · 932ac737-33ca-4afd-9869-0d48b391fcc9
Detects Ursnif C2 traffic.
Author: Florian Roth (Nextron Systems)
· 2019-10-01 (modified 2022-10-09) · logsource: product=windows category=process_creation · a018fdc3-46a3-44e5-9afb-2cd4af1d4b39
Detects a suspicious program execution in Outlook temp folder
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
· 2022-01-23 (modified 2023-02-22) · logsource: product=windows category=file_event · b1c50487-1967-4315-a026-6491686d860e
Detects the creation of a office macro file from a a suspicious process
Author: Omar Khaled (@beacon_exe)
· 2024-08-10 · logsource: product=macos category=process_creation · bf241472-f014-4f01-a869-96f99330ca8c
Detects the execution of the hdiutil utility in order to mount disk images.
Author: Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Elastic (idea)
· 2022-10-21 (modified 2023-02-10) · logsource: product=windows category=process_creation · c27515df-97a9-4162-8a60-dc0eeb51b775
Detects suspicious child processes of the Microsoft OneNote application. This may indicate an attempt to execute malicious embedded objects from a .one file.
Author: Tim Rauch (rule), Elastic (idea)
· 2022-10-21 · logsource: product=windows category=file_event · dbbd9f66-2ed3-4ca2-98a4-6ea985dd1a1c
Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.
Author: Maxim Pavlunin
· 2020-04-01 (modified 2023-04-12) · logsource: product=windows category=process_creation · e8a95b5e-c891-46e2-b33a-93937d3abc31
Detects a suspicious execution of a Microsoft HTML Help (HH.exe)
Author: Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
· 2025-07-22 · logsource: product=windows category=file_event · fabb0e80-030c-4e3e-a104-d09676991ac3
Detects the creation of files with suspicious file extensions in the temporary directory that Outlook uses when opening attachments.
This can be used to detect spear-phishing campaigns that use suspicious files as attachments, which may contain malicious code.
Author: Florian Roth (Nextron Systems)
· 2017-09-15 (modified 2021-11-27) · logsource: product=windows category=process_creation · fdd84c68-a1f6-47c9-9477-920584f94905
Detects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759
Rules tagged at the parent level (attack.t1566) 14
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Florian Roth (Nextron Systems)
· 2017-11-07 (modified 2023-05-18) · logsource: category=proxy · 00d0b5ab-1f55-4120-8e83-487c0a7baf19
Detects download of certain file types from hosts in suspicious TLDs
Author: Ahmed Farouk
· 2024-05-10 · logsource: category=proxy · 1ae64f96-72b6-48b3-ad3d-e71dff6c6398
Detects executables launched from external WebDAV shares using the WebDAV Explorer integration, commonly seen in initial access campaigns.
Author: Sittikorn S, frack113
· 2021-07-16 (modified 2023-08-17) · logsource: product=windows category=registry_set · 32b5db62-cb5f-4266-9639-0fa48376ac00
Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
Author: jamesc-grafana
· 2024-07-11 (modified 2025-12-08) · logsource: product=aws service=cloudtrail · 38e7f511-3f74-41d4-836e-f57dfa18eead
Detect when System Manager successfully executes commands against an instance.
Author: Micah Babinski
· 2023-08-21 · logsource: product=windows category=file_event · 4c55738d-72d8-490e-a2db-7969654e375f
Detects the creation of WebDAV temporary files with potentially suspicious extensions
Author: Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems)
· 2020-04-01 (modified 2023-04-12) · logsource: product=windows category=process_creation · 52cad028-0ff0-4854-8f67-d25dfcbc78b4
Detects a suspicious child process of a Microsoft HTML Help (HH.exe)
Author: Tim Rauch (rule), Elastic (idea)
· 2022-10-21 (modified 2022-12-28) · logsource: product=macos category=process_creation · 6e4dcdd1-e48b-42f7-b2d8-3b413fc58cb4
Detects when the macOS Script Editor utility spawns an unusual child process.
Author: Sittikorn S
· 2021-07-16 (modified 2022-10-09) · logsource: product=windows category=file_event · ad7085ac-92e4-4b76-8ce2-276d2c0e68ef
Detects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
Author: Florian Roth (Nextron Systems)
· 2017-03-13 (modified 2023-05-18) · logsource: category=proxy · b5de2919-b74a-4805-91a7-5049accbaefe
Detects executable downloads from suspicious remote systems
Author: Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Elastic (idea)
· 2022-10-21 (modified 2023-02-10) · logsource: product=windows category=process_creation · c27515df-97a9-4162-8a60-dc0eeb51b775
Detects suspicious child processes of the Microsoft OneNote application. This may indicate an attempt to execute malicious embedded objects from a .one file.
Author: Tim Rauch (rule), Elastic (idea)
· 2022-10-21 · logsource: product=windows category=file_event · dbbd9f66-2ed3-4ca2-98a4-6ea985dd1a1c
Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.
Author: Maxim Pavlunin
· 2020-04-01 (modified 2023-04-12) · logsource: product=windows category=process_creation · e8a95b5e-c891-46e2-b33a-93937d3abc31
Detects a suspicious execution of a Microsoft HTML Help (HH.exe)
Author: Austin Songer @austinsonger
· 2023-05-07 (modified 2026-04-27) · logsource: product=okta service=okta · ee39a9f7-5a79-4b0a-9815-d36b3cf28d3e
Detects when Okta FastPass prevents a known phishing site.
Author: Florian Roth (Nextron Systems)
· 2022-06-07 · logsource: product=windows category=process_creation · fcdf69e5-a3d3-452a-9724-26f2308bf2b1
Detects cases in which an ISO files is opend within an archiver like 7Zip or Winrar, which is a sign of phishing as threat actors put small ISO files in archives as email attachments to bypass certain filters and protective measures (mark of web)