→Exfiltration Over Web ServicetechniqueATT&CK mapping
Observed techniques
6 distinct
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
watering hole on an Israeli shipping company login page to harvest credentials (Mandiant)
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside UNC3890's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 4 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.002partialAnti-SpoofingT1566significantAnti-SpoofingT1566.002significantDefender for Cloud AppsT1567partialMultifactor AuthenticationT1566partialMultifactor AuthenticationT1566.002partialRole Based Access ControlT1059minimalAntimalwareT1059significantAntimalwareT1566significantAnti-PhishingT1566significantAnti-PhishingT1566.002significantAntiSpamT1566significantAntiSpamT1566.002significantAudit SolutionsT1566.002partialInformation ProtectionT1567significant
detect · 7 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.002significantApp GovernanceT1566significantAdvanced Threat HuntingT1189partialAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1566.002significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1189partialDefender for Cloud AppsT1567partialMicrosoft Defender for IdentityT1059minimalMicrosoft Defender for IdentityT1555minimalMicrosoft Defender for IdentityT1555.003minimalPreset Security PoliciesT1189significantPreset Security Policies
respond · 5 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.002partialAutomated Investigation and ResponseT1189significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.002significantAutomated Investigation and ResponseT1567significantIncident ResponseT1059minimalIncident ResponseT1566minimalQuarantine PoliciesT1566significantQuarantine PoliciesT1566.002significantSafe AttachmentsT1566significantATT&CK Simulation TrainingT1189partialATT&CK Simulation TrainingT1566partial
Countermeasures · D3FEND
Defensive techniques that counter UNC3890's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.