kevmap

TechniquesT1590 › T1590.002

T1590.002 DNS

reconnaissance — PRE · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
1
Sigma rules tagged attack.t1590.002
0
KEV CVEs mapped here
<p>Adversaries may gather information about the victim's DNS that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target’s subdomains, mail servers, and other hosts. DNS MX, TXT, and SPF records may also reveal the use of third party cloud and SaaS providers, such as Office 365, G Suite, Salesforce, or Zendesk.</p><p>Adversaries may gather this information in various ways, such as querying or otherwise collecting details via DNS/Passive DNS. DNS information may also be exposed to adversaries via online or other accessible data sets (ex: Search Open Technical Databases). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Technical Databases, Search Open Websites/Domains, or Active Scanning), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services).</p><p>Adversaries may also use DNS zone transfer (DNS query type AXFR) to collect all records from a misconfigured DNS server.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1590.002

Author: Zach Mathis · 2023-05-24 · logsource: product=windows service=dns-server · 6d444368-6da1-43fe-b2fc-44202430480e
Detects when a DNS zone transfer failed.
Techniques: T1590.002

Rules tagged at the parent level (attack.t1590) 2

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Axel Olsson · 2022-08-14 (modified 2024-02-15) · logsource: category=proxy · 1a9bb21a-1bb5-42d7-aa05-3219c7c8f47d
Detect the update check performed by Advanced IP/Port Scanner utilities.
Techniques: T1590
Author: Brandon George (blog post), Thomas Patzke · 2021-07-08 (modified 2024-03-22) · logsource: product=windows category=dns_query · ec82e2a5-81ea-4211-a1f8-37a0286df2c2
Detects DNS queries for IP lookup services such as "api.ipify.org" originating from a non browser process.
Techniques: T1590