T1566Phishing
T1566 — Phishing is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 20 detection use cases covering it and 131 threat-intel articles citing it.
Initial Access
20Use cases
131Articles
4Sub-techniques
1Tactic
Sub-techniques (4)
Use cases covering this technique (20)
CrowdStrike Falcon alert ingested Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator Gdrive suspicious file sharing Gsuite suspicious calendar invite Windows InProcServer32 New Outlook Form Windows Phishing Outlook Drop Dll In FORM Dir Zscaler Adware Activities Threat Blocked Zscaler Behavior Analysis Threat Blocked Zscaler CryptoMiner Downloaded Threat Blocked Zscaler Employment Search Web Activity Zscaler Exploit Threat Blocked Zscaler Legal Liability Threat Blocked Zscaler Malware Activity Threat Blocked Zscaler Phishing Activity Threat Blocked Zscaler Potentially Abused File Download Zscaler Privacy Risk Destinations Threat Blocked Zscaler Scam Destinations Threat Blocked Zscaler Virus Download threat blocked Suspicious Email - UBA Anomaly [LLM] Endpoint contact with F6 fraud-campaign hosting infra (212.127.73.235 / 167.86.100.68)Articles citing this technique (131)
crit Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation art-01
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-09
crit CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking art-77
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-78
crit Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller art-100
crit Begun, the Patch Wars have art-151
crit Winning 54% of the time art-215
crit ESET Threat Report H1 2026 art-222
crit When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website art-247
high Catan and Mouse art-262
high The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration art-312
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-402
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-640
crit ESET Threat Report H2 2025 art-732
high Defense in Depth art-1391
high Ethical hacking techniques art-1698
high Ethical Hacking: Top Tools art-1702
crit API Security Guide art-1751
high Securing the web (forward) art-1803
high Cybersecurity Hygiene 101 art-1824
crit Secure Python URL validation art-1937
high SREs bring ORDER(R) to CHAOS art-1965
crit XSS Attacks: The Next Wave art-3641