T1583.002 DNS Server
Subtécnica de T1583 Acquire Infrastructure
Adversaries may set up their own Domain Name System (DNS) servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS traffic for various tasks, including for Command and Control (ex: [Application Layer Protocol](https://attack.mitre.org/techniques/T1071)). Instead of hijacking existing DNS servers, adversaries may opt to configure and run their own…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
SigmaHQ no tiene reglas para esta técnica.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.