Skip to content
← LibraryTechnique entry
T1566Initial Access

Phishing

Send malicious messages to obtain access.

§ Where this technique fits

T1566 is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 18 approved dossiers in the registry, typically at step 2.7 on average.

Authoritative reference: attack.mitre.org/techniques/T1566/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    User Execution
    T1204 · Execution
    seen 7×
  2. 02seen 1×
  3. 03
    DNS Rebinding
    DNS-REBINDING · Lateral Movement
    seen 1×
  4. 04
    Entra App Consent Phishing
    C-AZ-APP-CONSENT · Privilege Escalation
    seen 1×
  5. 05
    FIDO2 caBLE / Hybrid Transport Abuse
    AUTH-FIDO2-CABLE · Credential Access
    seen 1×
  6. 06
    ISO / IMG Mounting → LNK Execution
    PAY-ISO-LNK · Execution
    seen 1×
  7. 07
    Insecure Direct Object Reference (IDOR)
    W-IDOR · Privilege Escalation
    seen 1×
  8. 08
    MFA Fatigue / Prompt Bombing
    PH-MFA-FATIGUE · Initial Access
    seen 1×