Initial Access
Spear Phishing with Malicious Attachment
• T1566.001 • A targeted email with a malicious attachment • Requires user execution to get code execution • High risk delivery as attachments are scrutinized by many layers of defense
Spear Phishing with a Link
• T1566.002 • A targeted email with a malicious link • Requires user execution to get code execution • Pretext in email should align with scenario of delivery • Can lower delivery risk by employing techniques to avoid security tools/blue teams
This post is licensed under CC BY 4.0 by the author.