T1566Phishing
T1566 — Phishing is a MITRE ATT&CK technique in the Initial Access tactic. Clankerusecase tracks 22 detection use cases covering it and 81 threat-intel articles citing it.
Initial Access
22Use cases
81Articles
4Sub-techniques
1Tactic
Sub-techniques (4)
Use cases covering this technique (22)
CrowdStrike Falcon alert ingested Microsoft Teams external-tenant chat from unverified IT-helpdesk impersonator Gdrive suspicious file sharing Gsuite suspicious calendar invite Windows InProcServer32 New Outlook Form Windows Phishing Outlook Drop Dll In FORM Dir Zscaler Adware Activities Threat Blocked Zscaler Behavior Analysis Threat Blocked Zscaler CryptoMiner Downloaded Threat Blocked Zscaler Employment Search Web Activity Zscaler Exploit Threat Blocked Zscaler Legal Liability Threat Blocked Zscaler Malware Activity Threat Blocked Zscaler Phishing Activity Threat Blocked Zscaler Potentially Abused File Download Zscaler Privacy Risk Destinations Threat Blocked Zscaler Scam Destinations Threat Blocked Zscaler Virus Download threat blocked Suspicious Email - UBA Anomaly [LLM] Inbound or outbound email involving AudiA6 mule-recruitment domains [LLM] Baileys messages.upsert event carrying a requestId field (exploit signature) [LLM] Roblox cheat/exploit download on enterprise endpoint (Lumma Stealer entry vector)Articles citing this technique (81)
high Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility art-74
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219
med Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise art-220
high 20+ Popular NPM Packages Compromised (Chalk, Debug, Strip-ANSI, Color-Convert, Wrap-ANSI...) art-537
crit ESET Threat Report H2 2025 art-647
high Defense in Depth art-1278