Phishing for Information: recognize the technique
What you are learning
Study how Phishing for Information supports the Reconnaissance phase. This lesson uses a bounded defender-analysis exercise rather than executing the adversary behavior.
- Describe Phishing for Information in ATT&CK terms.
- Explain how Phishing for Information can support later stages of an operation.
- Name at least one defensive observation or control relevant to the behavior.
Pre-compromise activity often leaves indirect signals rather than exploit artifacts. Understanding these behaviors helps defenders connect public exposure, operational preparation, and later intrusion activity without overstating what any single observation proves.
Review the technique description and identify what evidence a defender could use to recognize, investigate, or reduce the risk of this behavior. No external target interaction is required.
This module is a bounded ATT&CK/defender-analysis lesson. It does not require target interaction or submission of offensive findings.
Phishing for Information is part of Reconnaissance; the goal is to understand the adversary objective and the defender-visible evidence, not to reproduce harmful activity.
Use asset inventory, identity controls, provider telemetry, threat intelligence, and change/audit records where applicable. Correlate multiple observations before assigning adversary intent.