{"id":"T1665","name":"Hide Infrastructure","url":"https://attack.mitre.org/techniques/T1665","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0411","stix_id":"x-mitre-detection-strategy--ba2efedb-2670-4072-b56f-8f12daa31923","name":"Detection Strategy for Hide Infrastructure","url":"https://attack.mitre.org/detectionstrategies/DET0411","analytics":[{"id":"AN1148","stix_id":"x-mitre-analytic--9311924d-7d8f-489a-8105-058a60f572fc","name":"Analytic 1148","description":"Monitor DNS queries, proxy logs, and user-agent strings for anomalous patterns associated with adversary attempts to hide infrastructure. Defenders may observe DNS resolutions to short-lived domains, abnormal WHOIS registration data, or filtering of known defensive/responder IP addresses.","url":"https://attack.mitre.org/detectionstrategies/DET0411#AN1148","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=5156, 5157","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-security"},{"name":"dns:query","channel":"Excessive lookups for domains with suspicious WHOIS or short TTL values","data_component":"DC0101","data_component_name":"Domain Registration","log_source_slug":"dns-query"}],"mutable_elements":[{"field":"SuspiciousDomains","description":"List of domains registered with privacy-protected or suspicious WHOIS metadata."},{"field":"ResponderIPs","description":"Known incident response or scanning infrastructure IP ranges."}],"live":true,"detection_strategies":["DET0411"],"techniques":["T1665"]},{"id":"AN1149","stix_id":"x-mitre-analytic--c71bf861-9b5a-4f39-a53f-bb6f45f7a971","name":"Analytic 1149","description":"Detect adversaries filtering traffic or modifying server responses to evade scanning. Monitor iptables, nftables, or proxy configurations that deny or redirect requests from known scanning agents or defensive tools.","url":"https://attack.mitre.org/detectionstrategies/DET0411#AN1149","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of commands modifying iptables/nftables to block selective IPs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"Altered response metadata or blocked content based on user-agent or geolocation","data_component":"DC0106","data_component_name":"Response Metadata","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"BlockedAgents","description":"User-agent strings or scanning tools to monitor for selective filtering."}],"live":true,"detection_strategies":["DET0411"],"techniques":["T1665"]},{"id":"AN1150","stix_id":"x-mitre-analytic--9cf6c89d-73f7-42f8-b5e4-c87bf3abbb7d","name":"Analytic 1150","description":"Monitor unified logs for manipulation of proxy configurations, DNS resolution, or filtering rules. Adversaries may redirect responses or use trusted domains that later resolve to malicious C2 infrastructure.","url":"https://attack.mitre.org/detectionstrategies/DET0411#AN1150","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"System process modifications altering DNS/proxy settings","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"NSM:Flow","channel":"Suspicious changes in TLS certificate responses or redirected domains","data_component":"DC0104","data_component_name":"Response Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"TrustedHostingProviders","description":"Known hosting/CDN providers often abused to hide malicious C2 infrastructure."}],"live":true,"detection_strategies":["DET0411"],"techniques":["T1665"]},{"id":"AN1151","stix_id":"x-mitre-analytic--3f74d068-0a8b-4312-91f3-34da6c630c4a","name":"Analytic 1151","description":"Inspect network telemetry for adversary attempts to blend malicious traffic with legitimate flows using VPNs, proxies, or geolocation spoofing. Defensive teams may observe anomalous tunnels, encrypted sessions to suspicious domains, or geo-mismatched IP activity.","url":"https://attack.mitre.org/detectionstrategies/DET0411#AN1151","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"Encrypted tunnels or proxy traffic to non-standard destinations","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"GeoIPRanges","description":"Regions to monitor for unexpected or mismatched geolocation activity."}],"live":true,"detection_strategies":["DET0411"],"techniques":["T1665"]},{"id":"AN1152","stix_id":"x-mitre-analytic--4b16cb6e-7a81-4f97-a4ad-5e461e1cc154","name":"Analytic 1152","description":"Monitor VM-level DNS and network traffic logs for adversary-controlled domains or selective response behavior (e.g., dropped requests from security scanners).","url":"https://attack.mitre.org/detectionstrategies/DET0411#AN1152","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"DNS lookups resolving to domains with rapid changes in registration metadata","data_component":"DC0101","data_component_name":"Domain Registration","log_source_slug":"esxi-vmkernel"},{"name":"esxi:vmkernel","channel":"Suspicious traffic filtered or redirected by VM networking stack","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"MonitoredVMs","description":"Targeted virtual machines where adversaries may attempt to hide C2 traffic."}],"live":true,"detection_strategies":["DET0411"],"techniques":["T1665"]}],"live":true,"version":"1.0","techniques":["T1665"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}