Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0877 — Detection of DNS/Passive DNS
DET0877

Detection of DNS/Passive DNS

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN2009 Analytic 2009
PRE

Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.

Detected Techniques

1

Reconnaissance (1)

Details

MITRE ID
DET0877
STIX ID
x-mitre-detection-strategy--e7b468e8-3b2c-43ea-aabb-e8ba993bd7ae
Analytics
1
Techniques Detected
1
By Tactic
Reconnaissance
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.