Phishing: Spearphishing via Service T1566.003
Tactic: Initial Access
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.
Authoring guide
These 2 rules share fields, values, and exclusions.
Fields filtered most (13 distinct)
These fields appear most often in rule filters.
Top indicator values (54 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: Microsoft 365
Domain: Cloud