Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0891 — Detection of DNS Server
DET0891

Detection of DNS Server

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN2023 Analytic 2023
PRE

Monitor for queried domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Monitor for logged domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.

Domain Name None Domain Name None

Detected Techniques

1

Resource Development (1)

Details

MITRE ID
DET0891
STIX ID
x-mitre-detection-strategy--6a5e5149-9118-44e1-8933-0d2a8839df3a
Analytics
1
Techniques Detected
1
By Tactic
Resource Development
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.