Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Initial Access/ T1566.001

T1566.001Spearphishing Attachment

T1566.001 — Spearphishing Attachment is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 61 detection use cases covering it and 136 threat-intel articles citing it.

Initial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
61Use cases
136Articles
0Sub-techniques
1Tactic

Use cases covering this technique (61)

Abnormal Security: malicious email opened Internal delivery · alerting DD Email attachment opened from external sender Internal delivery · hunting DSP Email Attachments With Lots Of Spaces ESCU actions · hunting P Suspicious Email Attachment Extensions ESCU actions · hunting P GSuite Email Suspicious Attachment ESCU actions · hunting P Gsuite Email Suspicious Subject With Attachment ESCU actions · hunting P Gsuite Email With Known Abuse Web Service Link ESCU actions · hunting P Gsuite Suspicious Shared File Name ESCU actions · hunting P O365 Email Reported By Admin Found Malicious ESCU actions · alerting P O365 Email Reported By User Found Malicious ESCU actions · alerting P O365 Safe Links Detection ESCU actions · alerting P O365 Threat Intelligence Suspicious Email Delivered ESCU actions · hunting P O365 ZAP Activity Detection ESCU actions · hunting P Detect Outlook exe writing a zip file ESCU actions · hunting P Windows CAB File on Disk ESCU actions · hunting P Windows Defender ASR Audit Events ESCU actions · hunting P Windows Defender ASR Block Events ESCU actions · hunting P Windows Defender ASR Rules Stacking ESCU actions · hunting P Windows ISO LNK File Creation ESCU actions · hunting P Windows Office Product Dropped Cab or Inf File ESCU actions · alerting P Windows Office Product Dropped Uncommon File ESCU actions · hunting P Windows Office Product Loaded MSHTML Module ESCU actions · hunting P Windows Office Product Loading Taskschd DLL ESCU actions · hunting P Windows Office Product Loading VBE7 DLL ESCU actions · hunting P Windows Office Product Spawned Child Process For Download ESCU actions · alerting P Windows Office Product Spawned Control ESCU actions · alerting P Windows Office Product Spawned MSDT ESCU actions · alerting P Windows Office Product Spawned Rundll32 With No DLL ESCU actions · alerting P Windows Office Product Spawned Uncommon Process ESCU actions · alerting P Windows Phishing PDF File Executes URL Link ESCU actions · hunting P Windows Phishing Recent ISO Exec Registry ESCU actions · hunting P Windows Spearphishing Attachment Onenote Spawn Mshta ESCU actions · alerting P Windows Universal Data Link File Creation ESCU actions · hunting P Windows Spearphishing Attachment Connect To None MS Office Domain ESCU actions · hunting P MSHTML Module Load in Office Product ESCU actions · alerting P Office Application Drop Executable ESCU actions · alerting P Office Application Spawn Regsvr32 process ESCU actions · alerting P Office Application Spawn rundll32 process ESCU actions · alerting P Office Document Creating Schedule Task ESCU actions · alerting P Office Document Executing Macro Code ESCU actions · alerting P Office Document Spawned Child Process To Download ESCU actions · alerting P Office Product Spawn CMD Process ESCU actions · alerting P Office Product Spawning BITSAdmin ESCU actions · alerting P Office Product Spawning CertUtil ESCU actions · alerting P Office Product Spawning MSHTA ESCU actions · alerting P Office Product Spawning Rundll32 with no DLL ESCU actions · alerting P Office Product Spawning Windows Script Host ESCU actions · alerting P Office Product Spawning Wmic ESCU actions · alerting P Office Product Writing cab or inf ESCU actions · alerting P Office Spawning Control ESCU actions · alerting P Windows Office Product Spawning MSDT ESCU actions · alerting P Winword Spawning Cmd ESCU actions · alerting P Winword Spawning PowerShell ESCU actions · alerting P Winword Spawning Windows Script Host ESCU actions · alerting P [LLM] Inbound email from F6 fraud clone domain (ruspromexport-group.ru / info@ruspromexport-group.ru) Bespoke delivery · alerting DS [LLM] Inbound phishing from BEC sender domain 9i6pokerdepot.com (Q2 2026 ClickUp/pixeldrain chain) Bespoke delivery · alerting DSP [LLM] Inbound HTML-attachment lure exploiting Zimbra XSS (CVE-2025-66376) Bespoke delivery · hunting DS [LLM] Law-firm / order-confirmation lure delivering device-code phish via cacoo.com and allianceinvestigators.com Bespoke delivery · hunting DS [LLM] Mailcow quarantine XSS via EICAR + HTML in attachment filename (GHSA-2xjc-rg88-jvpp) Bespoke delivery · alerting DSΣPDD [LLM] Silver Fox Japan tax-season lure: inbound email with Japanese HR/ESOP subject + gofile.io URL or RAR/ZIP Bespoke delivery · alerting DS [LLM] Inbound email with HTML attachment linking to unpkg.com Beamglea package Bespoke delivery · alerting DSP

Articles citing this technique (136)