T1566 Phishing — Detection & Response
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary.
Coverage at a glance
- Detections shipped
- 4
- Avg. verdict time
- < 5 min
- Data sources
- 4+
Threat context
How adversaries use T1566 Phishing — Detection & Response
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary.
Phishing remains the leading initial access technique across all threat actor categories. Modern phishing campaigns frequently use adversary-in-the-middle (AiTM) proxy techniques (often via Evilginx or similar) to bypass MFA by capturing session cookies. Spearphishing via service (T1566.003) targeting Slack, Teams, LinkedIn, and GitHub has grown significantly as email security controls have improved, making messaging platforms a new phishing frontier.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| AiTM Phishing Session — New session token from suspicious IP after credential entry Authentication success immediately followed by a new session from a different IP, consistent with AiTM token theft. | Critical | Okta / Entra ID |
| Phishing Link Click Followed by Auth — Browser access to phishing domain correlated with subsequent login User clicks a URL categorised as phishing/credential-harvesting then authenticates within 5 minutes. | High | Proxy Logs + Identity Logs |
| Email Forwarding Rule Created Post-Login — Inbox rule created shortly after authentication Attacker who successfully phished credentials often creates forwarding rules immediately to maintain access to email. | High | M365 Audit Log |
| Defender for O365 Phishing Alert — High-confidence phishing email delivered to inbox Microsoft Defender classified an email as high-confidence phishing and delivered it to or intercepted it from an inbox. | Medium | Defender for Office 365 |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1539 Steal Web Session Cookie — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response: frequently asked questions
Can ManySignal detect AiTM phishing that bypasses MFA?
Yes. AiTM attacks produce a characteristic pattern: the user completes MFA on the phishing proxy, then the attacker uses the captured session token from a different IP. ManySignal detects this as a session originating from a new IP shortly after authentication completion, correlated with the user's initial sign-in location.
How does ManySignal handle phishing alerts from email security tools?
ManySignal ingests alerts from Defender for Office 365, Proofpoint, Mimecast, Abnormal Security, and other email security platforms. When a phishing alert fires for a user, ManySignal monitors that user's subsequent authentication and activity for signs of compromise.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.