// MITRE ATT&CK

T1684.001 · Impersonation

🎯 Stealth LinuxmacOSOffice SuiteSaaSWindows Sub-technique

Sub-technique of T1684 · Social Engineering.

Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims (via [Phishing for Information](https://attack.mitre.org/techniques/T1598), [Phishing](https://attac...

How to detect & mitigate it

Detecting Impersonation starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.