About

About the PH!SH framework

PH!SH is an open classification of phishing: how the attack works, what it pretends to be, and what it asks for. It comes out of the phishing that employees at Hoxhunt customers report: real emails that passed the email gateways and landed in inboxes. Every entry describes a pattern that recurs there.

Why phishing needs its own framework

MITRE ATT&CK® maps the whole intrusion lifecycle, and it compresses delivery into a small number of techniques. That’s the right level of detail for endpoint and network defense, but too coarse for the part of the attack a person actually sees.

ATT&CK does not describe the lure. PH!SH fills that gap and links back to ATT&CK, so an incident classified here still fits your existing reporting.

PH!SH does not classify the attacker’s objective. ATT&CK already names that layer, so the tactic columns on the ATT&CK view belong to ATT&CK rather than to PH!SH.

The three layers

Techniques The mechanics: how the message is delivered, disguised, and how credentials or payloads are collected. Answers “how”.
Themes The narrative and the brand or role being impersonated. Answers “what does it look like”.
Calls to action What the message asks the recipient to do, from clicking a link to moving money. Answers “what do they want me to do”.

How entries are numbered

Techniques use TE, themes TH, and calls to action CTA, each followed by a four-digit number. Sub-entries add a dotted suffix, so TE0005.3 is the PDF-file variant of malicious attachments.

IDs are stable. Entries are not renumbered when the framework grows, and retired entries stay published so old reports still resolve.

Relationship to other frameworks

Each entry lists the ATT&CK techniques it relates to. A mapping points at related work rather than claiming the two entries mean the same thing. A PH!SH entry is often more specific, and it may touch several ATT&CK techniques and vice versa.

The ATT&CK view exports a Navigator layer, which you can open in ATT&CK Navigator next to your own layers.