| name | hunting-for-spearphishing-indicators |
| description | Hunt for spearphishing campaign indicators across email logs, endpoint telemetry, and network data to detect targeted email attacks. Use when hunting for spearphishing campaign indicators across email logs, endpoint telemetry,. |
| domain | cybersecurity |
| tags | ["threat-hunting","mitre-attack","spearphishing","initial-access","email-security","t1566","proactive-detection"] |
| subdomain | threat-hunting |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| d3fend_techniques | ["File Metadata Consistency Validation","Application Protocol Command Analysis","Identifier Analysis","Content Format Conversion","Message Analysis"] |
| nist_csf | ["DE.CM-01","DE.AE-02","DE.AE-07","ID.RA-05"] |
Hunting For Spearphishing Indicators
Overview
Cybersecurity skill for hunting for spearphishing indicators. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"hunting for spearphishing indicators"
-
"When proactively hunting for indicators of hunting for spearphishing indicators"
-
"After threat intelligence indicates active campaigns using these techniques"
-
"During incident response to scope compromise related to these techniques"
-
When proactively hunting for indicators of hunting for spearphishing indicators in the environment
-
After threat intelligence indicates active campaigns using these techniques
-
During incident response to scope compromise related to these techniques
-
When EDR or SIEM alerts trigger on related indicators
-
During periodic security assessments and purple team exercises
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) k, v IOC_PATTERNS.items()}