// MITRE ATT&CK

T1534 · Internal Spearphishing

🎯 Lateral Movement LinuxmacOSOffice SuiteSaaSWindows

After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization. Internal spearphishing is multi-staged campaign where a legitimate account is init...

How to detect & mitigate it

Detecting Internal Spearphishing starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.