Compromise Infrastructure: DNS Server T1584.002

Tactic: Resource Development

Adversaries may compromise third-party DNS servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS traffic for various tasks, including for Command and Control (ex: Application Layer Protocol). Instead of setting up their own DNS servers, adversaries may compromise third-party DNS servers in support of operations.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (7 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
NewDnsSecState1eq 1OFF
OldDnsSecState1eq 1ON
ServiceName1eq 1dns.googleapis.com
Severity1eq 1NOTICE
ZoneContext1is_not_null 1
gcp::method_name1in 1dns.managedZones.patch, dns.managedZones.update
gcp::resource_type1eq 1dns_managed_zone

Top indicator values (7 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
NewDnsSecStateeq
OFF
1
OldDnsSecStateeq
ON
1
ServiceNameeq
dns.googleapis.com
1
Severityeq
NOTICE
14
gcp::method_namein
dns.managedZones.patch
1
gcp::method_namein
dns.managedZones.update
1
gcp::resource_typeeq
dns_managed_zone
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: GCP

Domain: Cloud

Kusto 1 rule