{
  "technique_id": "T1534",
  "name": "Internal Spearphishing",
  "tactics": [
    "Lateral Movement"
  ],
  "platforms": [
    "Linux",
    "macOS",
    "Office Suite",
    "SaaS",
    "Windows"
  ],
  "summary": "After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization. Internal spearphishing is multi-staged campaign where a legitimate account is initially compromised either by controlling the user's device or by compromising the account credentials of the user...",
  "generated_by": "SOC Response Atlas by Basyrix"
}