Compliance Node Overview
MITRE ATT&CK T1566.004 (Spearphishing Voice) is an Enterprise Initial Access sub-technique of T1566 (Phishing). Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that is employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Affected platforms: Linux, macOS, Windows, Identity Provider. MITRE-documented mitigations include M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CA-07, CM-02, CM-06, IA-09, RA-05, SC-07, SC-20.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1566/004/
SHA-256 integrity: fca18e8cbd61b1c3ebd92df1431bd36b072be7715f56aefb4a260442cf94d0b6
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1566.004: Spearphishing Voice (https://attack.mitre.org/techniques/T1566/004/)
- MITRE ATT&CK Tactic TA0001: Initial Access (https://attack.mitre.org/tactics/TA0001/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access