TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Red Canary

New: Use response actions to update Zscaler policies and block threats

Dylan Solomon · 2026-04-14 · Read original ↗

ATT&CK techniques detected

2 predictions
T1566.002Spearphishing Link
79%
"new : use response actions to update zscaler policies and block threats the intel teams here at red canary and zscaler have seen some notable social engineering attacks recently. bad actors get an employee email address and run a program to plug it into a bunch of legitimate site…"
T1598Phishing for Information
32%
"new : use response actions to update zscaler policies and block threats the intel teams here at red canary and zscaler have seen some notable social engineering attacks recently. bad actors get an employee email address and run a program to plug it into a bunch of legitimate site…"

Summary

A new integration gives teams an easy way to update Zscaler Internet Access (ZIA) network policies using Red Canary response actions.