Spearphishing Attachment (T1598.002)

View on ATT&CK

In Playbook

Associated Tactics

  • Reconnaissance

Reconnaissance (TA0043)

The adversary is trying to gather information they can use to plan future operations. Reconnaissance consists of techniques that involve adversaries actively or passively gathering information that can be used to support targeting. Such information may include details of the victim organization, infrastructure, or staff/personnel. This information can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as using gathered information to plan and execute Initial Access, to scope and prioritize post-compromise objectives, or to drive and lead further Reconnaissance efforts.

View on ATT&CK

Procedure Examples

Description Source(s)
Australian Cyber Security Centre. (2012, December). Mitigating Spoofed Emails Using Sender Policy Framework. Retrieved October 19, 2020. ACSC Email Spoofing
Ducklin, P. (2020, October 2). Serious Security: Phishing without links – when phishers bring along their own web pages. Retrieved October 20, 2020. Sophos Attachment
Microsoft. (2020, October 13). Anti-spoofing protection in EOP. Retrieved October 19, 2020. Microsoft Anti Spoofing
Ryan Hanson. (2016, September 24). phishery. Retrieved October 23, 2020. GitHub Phishery