Techniques › T1590 › T1590.002
T1590.002 DNS
reconnaissance — PRE · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
1
Sigma rules tagged attack.t1590.002
0
KEV CVEs mapped here
<p>Adversaries may gather information about the victim's DNS that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target’s subdomains, mail servers, and other hosts. DNS MX, TXT, and SPF records may also reveal the use of third party cloud and SaaS providers, such as Office 365, G Suite, Salesforce, or Zendesk.</p><p>Adversaries may gather this information in various ways, such as querying or otherwise collecting details via DNS/Passive DNS. DNS information may also be exposed to adversaries via online or other accessible data sets (ex: Search Open Technical Databases). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Technical Databases, Search Open Websites/Domains, or Active Scanning), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services).</p><p>Adversaries may also use DNS zone transfer (DNS query type AXFR) to collect all records from a misconfigured DNS server.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0843 Detection of DNS v1.0
AN1975 PREMuch of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1590.002
Author: Zach Mathis
· 2023-05-24 · logsource: product=windows service=dns-server · 6d444368-6da1-43fe-b2fc-44202430480e
Detects when a DNS zone transfer failed.
Rules tagged at the parent level (attack.t1590) 2
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Axel Olsson
· 2022-08-14 (modified 2024-02-15) · logsource: category=proxy · 1a9bb21a-1bb5-42d7-aa05-3219c7c8f47d
Detect the update check performed by Advanced IP/Port Scanner utilities.
Author: Brandon George (blog post), Thomas Patzke
· 2021-07-08 (modified 2024-03-22) · logsource: product=windows category=dns_query · ec82e2a5-81ea-4211-a1f8-37a0286df2c2
Detects DNS queries for IP lookup services such as "api.ipify.org" originating from a non browser process.