166 terms · 75/46/45
Technique № 001 · class: initial access

Phishing

Phishing as a technique involves sending fraudulent emails, SMS messages, or chat messages to trick the victim into clicking a malicious link, opening an infected attachment, or entering credentials on a fake page.

Term

description · examples · notes

Phishing as a technique involves sending fraudulent emails, SMS messages, or chat messages to trick the victim into clicking a malicious link, opening an infected attachment, or entering credentials on a fake page.

Description

The technique is used for both mass campaigns and highly personalized attacks. Successful phishing typically serves as the entry point for further escalation within the target environment.

Examples

  • Email with a fake login page that harvests user credentials
  • SMS message with a package tracking link leading to a malicious site
  • Chat message with an infected document attachment
  • Personalized email referencing an internal project with a malicious attachment

Notes

  • Phishing remains the most common initial access vector in the majority of reported incidents.

Mentioned in the news

Composite

Threats

used by 14

Defenses

countered by 10