MITRE ATT&CK Technique
T1566.003
1 query tagged with this technique.
View on MITRE ATT&CK →
-
Hunting
Hunt Teams Phishing Then Suspicious Login Correlation
Teams phishing messages correlated with subsequent suspicious sign-ins for the same recipient — deals with ExternalAccess not being populated by falling back to sender-domain-outside-org.