Pre-compromise mitigations involve proactive measures and defenses implemented to prevent adversaries from successfully identifying and exploiting weaknesses during the Reconnaissance and Resource Development phases of an attack. These activities focus on reducing an organization's attack surface, identify adversarial preparation efforts, and increase the difficulty for attackers to conduct successful operations. This mitigation can be implemented through the following measures: Limit Information Exposure: - Regularly audit and sanitize publicly available data, including job posts, websites, and social media. - Use tools like OSINT monitoring platforms (e.g., SpiderFoot, Recon-ng) to identify leaked information. Protect Domain and DNS Infrastructure: - Enable DNSSEC and use WHOIS privacy protection. - Monitor for domain hijacking or lookalike domains using services like RiskIQ or Domain…
MITRE mitigation sourceSearch Threat Vendor Data
Threat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by other adversaries that may align with their target industries, capabilities/objectives, or other operational concerns. These reports may include descriptions of behavior, detailed breakdowns of attacks, atomic indicators such as malware hashes or IP addresses, timelines of a group’s activity, and more. Adversaries may change their behavior when planning their future operations. Adversaries have been observed replacing atomic indicators mentioned in blog posts in under a week.(Citation: Google Cloud Threat Intelligence VMWare ESXi Zero-Day 2023) Adversaries have also been seen searching for their own domain names in threat vendor data and then taking them down, likely to avoid seizure or further investigation.(Citation: Sentinel One Contagious Interview ClickFix September 2025) This technique is distinct from [Threat Intel Vendors](https://attack.mitre.org/techniques/T1597/001) in that it describes threat actors performing reconnaissance on their own activity, not in search of victim information.
Open in the interactive knowledge mesh
Detection overview
Use the published detection strategies below and validate required telemetry in the target environment.
Observed groups
Cyber Knowledge context
Use these routes to move from the ATT&CK behavior into explanation, implementation, evidence handling, validation, and defensive operations. Relevance is generated from explicit identifiers/names and governed topic mappings; it is not attribution evidence.
Cyber Threat Intelligence (CTI) · topic-match · 88/100Module 3 — Core Frameworks Models
Cyber Threat Intelligence (CTI) · topic-match · 88/100Module 5 — Analysis Techniques Tradecraft
Cyber Threat Intelligence (CTI) · topic-match · 88/100Module 6 — The Threat Actor Landscape
Cyber Threat Intelligence (CTI) · topic-match · 88/100Module 7 — Intelligence Products Sharing
Cyber Threat Intelligence (CTI) · topic-match · 87/100Module 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · topic-match · 81/100Module 9 — Tools of the Trade
Cyber Threat Intelligence (CTI) · topic-match · 81/100Module 2 — The Intelligence Cycle Intelligence Types
Cyber Threat Intelligence (CTI) · topic-match · 78/100Module 10 — Career Path Continuing Education
Cyber Threat Intelligence (CTI) · topic-match · 78/100Search engines, web archives, public records, and documents
OSINT & Reconnaissance · topic-match · 69/100Automation, APIs, entity graphs, normalization, and data engineering
OSINT & Reconnaissance · topic-match · 63/100AI-assisted OSINT with bounded tools, citations, and human review
OSINT & Reconnaissance · topic-match · 60/100
MITRE mitigations
MITRE detection strategies and analytics
- AN1998 · Analytic 1998 — Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.