{"id":"T1584","name":"Compromise Infrastructure","url":"https://attack.mitre.org/techniques/T1584","tactics":["resource-development"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0885","stix_id":"x-mitre-detection-strategy--7f3e2c35-7394-4cc6-baef-73a830930953","name":"Detection of Compromise Infrastructure","url":"https://attack.mitre.org/detectionstrategies/DET0885","analytics":[{"id":"AN2017","stix_id":"x-mitre-analytic--816aaddd-dc6d-49da-8ecd-8afde6278181","name":"Analytic 2017","description":"Once adversaries have provisioned compromised infrastructure (ex: a server for use in command and control), internet scans may help proactively discover compromised infrastructure. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021)\nConsider monitoring for anomalous changes to domain registrant information and/or domain resolution information that may indicate the compromise of a domain. Efforts may need to be tailored to specific domains of interest as benign registration and resolution changes are a common occurrence on the internet.\nMonitor for queried domain name system (DNS) registry data that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nMonitor for logged domain name system (DNS) data that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nMonitor for contextual data about an Internet-facing resource gathered from a scan, such as running services or ports that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.","url":"https://attack.mitre.org/detectionstrategies/DET0885#AN2017","platforms":["PRE"],"log_source_references":[{"name":"Internet Scan","channel":"None","data_component":"DC0104","data_component_name":"Response Content","log_source_slug":"internet-scan"},{"name":"Domain Name","channel":"None","data_component":"DC0101","data_component_name":"Domain Registration","log_source_slug":"domain-name"},{"name":"Domain Name","channel":"None","data_component":"DC0103","data_component_name":"Active DNS","log_source_slug":"domain-name"},{"name":"Domain Name","channel":"None","data_component":"DC0096","data_component_name":"Passive DNS","log_source_slug":"domain-name"},{"name":"Internet Scan","channel":"None","data_component":"DC0106","data_component_name":"Response Metadata","log_source_slug":"internet-scan"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0885"],"techniques":["T1584"]}],"live":true,"version":"1.0","techniques":["T1584"]}],"sigma_rules":[{"id":"13cfeb75-9e33-4d04-b0f7-ab8faaa95a59","title":"Windows Update Error","author":"frack113","status":"stable","level":"informational","date":"2021-12-04","modified":"2023-09-07","description":"Detects Windows update errors including installation failures and connection issues. Defenders should observe this in case critical update KBs aren't installed.\n","references":["https://github.com/nasbench/EVTX-ETW-Resources/blob/f1b010ce0ee1b71e3024180de1a3e67f99701fe4/ETWProvidersManifests/Windows10/1903/W10_1903_Pro_20200714_18362.959/WEPExplorer/Microsoft-Windows-WindowsUpdateClient.xml"],"logsource":{"product":"windows","service":"system"},"tags":["attack.impact","attack.resource-development","attack.t1584"],"path":"rules/windows/builtin/system/microsoft_windows_windows_update_client/win_system_susp_system_update_error.yml","techniques":["T1584"],"cves":[]},{"id":"1ae64f96-72b6-48b3-ad3d-e71dff6c6398","title":"Suspicious External WebDAV Execution","author":"Ahmed Farouk","status":"test","level":"high","date":"2024-05-10","modified":null,"description":"Detects executables launched from external WebDAV shares using the WebDAV Explorer integration, commonly seen in initial access campaigns.\n","references":["https://dear-territory-023.notion.site/WebDav-Share-Testing-e4950fa0c00149c3aa430d779b9b1d0f?pvs=4","https://micahbabinski.medium.com/search-ms-webdav-and-chill-99c5b23ac462","https://www.trendmicro.com/en_no/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html","https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.resource-development","attack.t1584","attack.t1566"],"path":"rules/web/proxy_generic/proxy_webdav_external_execution.yml","techniques":["T1584","T1566"],"cves":[]},{"id":"4c55738d-72d8-490e-a2db-7969654e375f","title":"WebDAV Temporary Local File Creation","author":"Micah Babinski","status":"test","level":"medium","date":"2023-08-21","modified":null,"description":"Detects the creation of WebDAV temporary files with potentially suspicious extensions","references":["https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html","https://micahbabinski.medium.com/search-ms-webdav-and-chill-99c5b23ac462","https://dear-territory-023.notion.site/WebDav-Share-Testing-e4950fa0c00149c3aa430d779b9b1d0f?pvs=4"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.initial-access","attack.resource-development","attack.t1584","attack.t1566","detection.threat-hunting"],"path":"rules-threat-hunting/windows/file/file_event/file_event_win_webdav_tmpfile_creation.yml","techniques":["T1584","T1566"],"cves":[]},{"id":"a39d7fa7-3fbd-4dc2-97e1-d87f546b1bbc","title":"Program Executions in Suspicious Folders","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2018-01-23","modified":"2021-11-27","description":"Detects program executions in suspicious non-program folders related to malware or hacking activity","references":["Internal Research"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.t1587","attack.t1584","attack.resource-development"],"path":"rules/linux/auditd/syscall/lnx_auditd_susp_exe_folders.yml","techniques":["T1587","T1584"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}