M ManySignal
T1566 MITRE ATT&CK

T1566 Phishing — Detection & Response

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary.

Coverage at a glance

Detections shipped
4
Avg. verdict time
< 5 min
Data sources
4+

Threat context

How adversaries use T1566 Phishing — Detection & Response

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary.

Phishing remains the leading initial access technique across all threat actor categories. Modern phishing campaigns frequently use adversary-in-the-middle (AiTM) proxy techniques (often via Evilginx or similar) to bypass MFA by capturing session cookies. Spearphishing via service (T1566.003) targeting Slack, Teams, LinkedIn, and GitHub has grown significantly as email security controls have improved, making messaging platforms a new phishing frontier.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

AiTM Phishing Session — New session token from suspicious IP after credential entry

Authentication success immediately followed by a new session from a different IP, consistent with AiTM token theft.

Critical Okta / Entra ID

Phishing Link Click Followed by Auth — Browser access to phishing domain correlated with subsequent login

User clicks a URL categorised as phishing/credential-harvesting then authenticates within 5 minutes.

High Proxy Logs + Identity Logs

Email Forwarding Rule Created Post-Login — Inbox rule created shortly after authentication

Attacker who successfully phished credentials often creates forwarding rules immediately to maintain access to email.

High M365 Audit Log

Defender for O365 Phishing Alert — High-confidence phishing email delivered to inbox

Microsoft Defender classified an email as high-confidence phishing and delivered it to or intercepted it from an inbox.

Medium Defender for Office 365

T1566 Phishing — Detection & Response: frequently asked questions

Can ManySignal detect AiTM phishing that bypasses MFA?

Yes. AiTM attacks produce a characteristic pattern: the user completes MFA on the phishing proxy, then the attacker uses the captured session token from a different IP. ManySignal detects this as a session originating from a new IP shortly after authentication completion, correlated with the user's initial sign-in location.

How does ManySignal handle phishing alerts from email security tools?

ManySignal ingests alerts from Defender for Office 365, Proofpoint, Mimecast, Abnormal Security, and other email security platforms. When a phishing alert fires for a user, ManySignal monitors that user's subsequent authentication and activity for signs of compromise.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.