T1590.001 Domain Properties
Sub-technique of T1590 Gather Victim Network Information
Adversaries may gather information about the victim's network domain(s) that can be used during targeting. Information about domains and their properties may include a variety of details, including what domain(s) the victim owns as well as administrative data (ex: name, registrar, etc.) and more directly actionable information such as contacts (email addresses and phone numbers), business…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- PUA - Crassus Executionhightest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.