kevmap

TechniquesT1584.005 › AN2015

AN2015 Analytic 2015

PRE · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Phishing, Endpoint Denial of Service, or Network Denial of Service.</p>
Detects
T1584.005 Botnet
Part of
DET0883 Detection of Botnet

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2020-25506D-Link DNS-320 DeviceMapped
CVE-2020-29557D-Link DIR-825 R1 DevicesMapped