About the PH!SH framework
PH!SH is an open classification of phishing: how the attack works, what it pretends to be, and what it asks for. It comes out of the phishing that employees at Hoxhunt customers report: real emails that passed the email gateways and landed in inboxes. Every entry describes a pattern that recurs there.
Why phishing needs its own framework
MITRE ATT&CK® maps the whole intrusion lifecycle, and it compresses delivery into a small number of techniques. That’s the right level of detail for endpoint and network defense, but too coarse for the part of the attack a person actually sees.
ATT&CK does not describe the lure. PH!SH fills that gap and links back to ATT&CK, so an incident classified here still fits your existing reporting.
PH!SH does not classify the attacker’s objective. ATT&CK already names that layer, so the tactic columns on the ATT&CK view belong to ATT&CK rather than to PH!SH.
The three layers
How entries are numbered
Techniques use TE, themes TH, and calls to action CTA, each followed by a four-digit number. Sub-entries add a dotted suffix, so TE0005.3 is the PDF-file variant of malicious attachments.
IDs are stable. Entries are not renumbered when the framework grows, and retired entries stay published so old reports still resolve.
Relationship to other frameworks
Each entry lists the ATT&CK techniques it relates to. A mapping points at related work rather than claiming the two entries mean the same thing. A PH!SH entry is often more specific, and it may touch several ATT&CK techniques and vice versa.
The ATT&CK view exports a Navigator layer, which you can open in ATT&CK Navigator next to your own layers.