Techniques › T1584.002 › AN2023
AN2023 Analytic 2023
PRE · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Monitor for queried domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Monitor for logged domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.</p>
- Detects
- T1584.002 DNS Server
- Part of
- DET0891 Detection of DNS Server
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| Domain Name | None | DC0103 Active DNS |
| Domain Name | None | DC0096 Passive DNS |