Post

Initial Access

Spear Phishing with Malicious Attachment

• T1566.001 • A targeted email with a malicious attachment • Requires user execution to get code execution • High risk delivery as attachments are scrutinized by many layers of defense

Spear Phishing with a Link

• T1566.002 • A targeted email with a malicious link • Requires user execution to get code execution • Pretext in email should align with scenario of delivery • Can lower delivery risk by employing techniques to avoid security tools/blue teams

This post is licensed under CC BY 4.0 by the author.