// MITRE ATT&CK
T1566.002 · Spearphishing Link
Sub-técnica de T1566 · Phishing.
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in ema...
¿Cómo detectarlo y mitigarlo?
La detección de Spearphishing Link parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Técnicas relacionadas
T1195.001
Compromise Software Dependencies and Development Tools T1566.001
Spearphishing Attachment T1195.003
Compromise Hardware Supply Chain T1195
Supply Chain Compromise T1190
Exploit Public-Facing Application T1659
Content Injection T1199
Trusted Relationship T1566
Phishing
Compromise Software Dependencies and Development Tools T1566.001
Spearphishing Attachment T1195.003
Compromise Hardware Supply Chain T1195
Supply Chain Compromise T1190
Exploit Public-Facing Application T1659
Content Injection T1199
Trusted Relationship T1566
Phishing
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.