Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0245 — Detection Strategy for Spearphishing Voice across OS platforms
DET0245

Detection Strategy for Spearphishing Voice across OS platforms

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0683 Analytic 0683
Windows

Monitor call log records from corporate devices for unusual or unauthorized numbers, especially repeated calls to/from known malicious phone numbers. Correlate with subsequent system events (e.g., browser navigation, remote management tool execution).

ApplicationLog:CallRecords Outbound or inbound calls to high-risk or blocklisted numbers
[PhoneNumberBlocklist] List of known malicious or suspicious phone numbers; must be tuned per environment
[TimeWindow] Threshold for correlating call events with subsequent suspicious system activity
AN0684 Analytic 0684
Linux

Audit VoIP/SIP logs for suspicious outbound calls or call setup messages to unusual endpoints. Correlate with user activity such as browser execution or package installation following the call.

networkdevice:syslog SIP REGISTER, INVITE, or unusual call destination metadata
[CallDestinationPatterns] Regular expressions or rules for spotting abnormal call destinations
[UserContext] Expected users who initiate VoIP traffic vs. anomalous accounts
AN0685 Analytic 0685
macOS

Monitor Facetime, iMessage, or SIP client logs for anomalous voice call attempts. Link to subsequent user execution events (downloads, RMM installs) triggered post-call.

macos:unifiedlog Outgoing or incoming calls with non-standard caller IDs or unusual metadata
[CallerIDPatterns] Patterns of spoofed caller IDs that must be tuned based on region and telecom provider
[PayloadCorrelation] Define what follow-on events (browser downloads, execution) to correlate with call logs
AN0686 Analytic 0686
Identity Provider

Correlate MFA push fatigue or unusual consent grant attempts with call activity where adversaries may have socially engineered the user over voice.

m365:unified Unusual MFA requests or OAuth consent events temporally aligned with user-reported vishing call
[MFARequestThreshold] Number of MFA push requests within a timeframe aligned to a suspicious call
[ConsentGrantPatterns] Unusual OAuth consent URLs or delegated scopes

Detected Techniques

1

Details

MITRE ID
DET0245
STIX ID
x-mitre-detection-strategy--ec33e12c-e0f1-426d-a453-fa5ae4d3cf9a
Analytics
4
Techniques Detected
1
By Tactic
Initial Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.