Compliance Node Overview
MITRE ATT&CK T1566.001 covers adversary delivery of malicious files via email attachments to trick users into execution. Office documents with malicious macros, OLE objects, ISO/IMG containers bypassing Mark of the Web, OneNote attachments, and HTML smuggling are the dominant vectors as of 2024-2025. Microsoft Threat Intelligence reports document millions of spearphishing attachment attempts daily. Compliance obligations include NIST SP 800-53 SI-3 (Malicious Code Protection), AT-2 (Literacy Training), ISO 27001 A.8.7, A.6.3, PCI DSS Req 12.6, HIPAA 164.308(a)(5), and CISA Phishing Guidance.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1566/001/
SHA-256 integrity: 867d51d738c33b6501f5730c82e8671e7e8a1cf9fa3af5f3b4c84f9ff0cd822b
Primary Citations — 8 traced to source
- MITRE ATT&CK Technique T1566.001: Spearphishing Attachment (https://attack.mitre.org/techniques/T1566/001/)
- NIST SP 800-53 Rev 5: SI-3 (Malicious Code Protection), AT-2 (Literacy Training)
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.