kevmap

TechniquesT1584.002 › AN2023

AN2023 Analytic 2023

PRE · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Monitor for queried domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Monitor for logged domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.</p>
Detects
T1584.002 DNS Server
Part of
DET0891 Detection of DNS Server

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
Domain NameNoneDC0103 Active DNS
Domain NameNoneDC0096 Passive DNS