Version history

Releases and changes

IDs are stable across releases. We add new entries, refine descriptions, and keep retired entries published.

Current release

Layers 34 techniques (58 sub-techniques), 48 themes (28 sub-themes), and 7 calls to action.
Mapped entries 111 entries carry a mapping to MITRE ATT&CK®.
Crosswalk Mappings target MITRE Enterprise ATT&CK v19.
Coverage Contact methods include email, SMS, Teams, phone calls, and website contact forms.
Data snapshot Framework data as of 9 September 2026 (framework hash 662d5065).
License CC BY 4.0 for framework content. See License and citation.

Change policy

Stable IDs An ID always refers to the same concept. Nothing is renumbered.
Refinements Every change to a description or a mapping is listed in the changelog below with its date. The version number changes when entries are added or retired.
Retirement An entry that no longer occurs is marked retired rather than deleted, so historical reports still resolve.

Changelog

v1.0, 9 September 2026 First public release: techniques, themes, and calls to action. Crosswalk aligned to Enterprise ATT&CK v19: T1660 named Phishing, T1553 placed under Defense Impairment, Impersonation (T1684.001) used where the entry describes impersonation, Office Files, Attachment Padding, Fake CAPTCHA, Open Redirect, Encoded URL, and Automated Personalization re-mapped. TH0018 description rewritten. Typos fixed in TE0007 and TH0012. Terminal punctuation normalized. Crosswalk reduced to high-confidence mappings on 10 September 2026: generic parents beside a precise sub-technique, attacker preparation the message does not show, and delivery mechanisms on themes were removed, and credential harvesters now map to T1598.003 instead of T1056.003.

Earlier work

PH!SH began as an internal classification used to label reported phishing at scale. This is its first public form.