What MITRE ATT&CK T1566.002: Spearphishing Link (Sub-Technique of T1566 - Initial Access) requires
MITRE ATT&CK T1566.002 covers adversary delivery of malicious URLs via email to phish credentials or deliver malware. Modern attackers use look-alike domains, recently-registered domains, URL shorteners, legitimate cloud-hosted phishing pages (Microsoft 365, AWS S3, Cloudflare Workers), and adversary-in-the-middle phishing kits (EvilGinx2, Modlishka, Tycoon 2FA, Mamba 2FA). Compliance: NIST 800-53 SI-3, AT-2, ISO 27001 A.8.7, A.6.3, PCI DSS Req 12.6, HIPAA 164.308(a)(5).
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1566/002/
SHA-256 integrity: 2f1f7564d87554e3929ed9e5110914531a48ffedc754451eadded28478f4f3a4
Primary Citations — 8 traced to source
- MITRE ATT&CK Technique T1566.002: Spearphishing Link (https://attack.mitre.org/techniques/T1566/002/)
- NIST SP 800-53 Rev 5: SI-3, AT-2
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1566-002-spearphishing-link.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1566-002-spearphishing-link.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1566-002-spearphishing-link
- Back to registry: Browse all 10,085 compliance nodes