Basyrix SOC Response Atlas by Basyrix

Initial Access

T1566 — Phishing

Adversaries may send phishing messages — spearphishing links, attachments, or service-based lures — to gain initial access via credential harvesting, malicious attachments, or social engineering.

Treat a reported or detected phishing message as a potential initial access event, not just a spam nuisance. Confirm whether the message was opened, links clicked, attachments executed, or credentials entered, and scope to every recipient of the same campaign.

Platforms

Office 365, SaaS, Windows, Linux, macOS

Priority / status

high / complete

Evidence to collect

  • Sender address and display name
  • Message headers (SPF/DKIM/DMARC results)
  • Recipient list
  • URLs and attachment hashes
  • Click/detonation verdicts
  • Any subsequent sign-in or endpoint activity