kevmap

TechniquesT1102.001 › AN0158

AN0158 Analytic 0158

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).</p>
Detects
T1102.001 Dead Drop Resolver
Part of
DET0058 Detection Strategy for Web Service: Dead Drop Resolver

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=3, 22DC0082 Network Connection Creation
etw:Microsoft-Windows-NDIS-PacketCaptureTLS Handshake/Network FlowDC0085 Network Traffic Content

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TargetDomainFQDN or IP for the hosting site of the dead drop (e.g., pastebin.com, twitter.com)
TimeWindowDefines how close in time the suspicious network and process behavior must occur
UserContextFilter by user or system accounts to reduce noise