T1102.001 Dead Drop Resolver
Sub-technique of T1102 Web Service
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers. Popular websites and…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- PwnDrp Accesscriticaltest · proxy
- New Connection Initiated To Potential Dead Drop Resolver Domainhightest · windows
- Raw Paste Service Accesshightest · proxy
- Network Connection Initiated To AzureWebsites.NET By Non-Browser Processmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.