// MITRE ATT&CK
T1566.003 · Spearphishing via Service
Sub-technique of T1566 · Phishing.
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than dire...
How to detect & mitigate it
Detecting Spearphishing via Service starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1195.001
Compromise Software Dependencies and Development Tools T1566.002
Spearphishing Link T1566.001
Spearphishing Attachment T1195.003
Compromise Hardware Supply Chain T1195
Supply Chain Compromise T1190
Exploit Public-Facing Application T1659
Content Injection T1199
Trusted Relationship
Compromise Software Dependencies and Development Tools T1566.002
Spearphishing Link T1566.001
Spearphishing Attachment T1195.003
Compromise Hardware Supply Chain T1195
Supply Chain Compromise T1190
Exploit Public-Facing Application T1659
Content Injection T1199
Trusted Relationship
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.