Pre-compromise mitigations involve proactive measures and defenses implemented to prevent adversaries from successfully identifying and exploiting weaknesses during the Reconnaissance and Resource Development phases of an attack. These activities focus on reducing an organization's attack surface, identify adversarial preparation efforts, and increase the difficulty for attackers to conduct successful operations. This mitigation can be implemented through the following measures: Limit Information Exposure: - Regularly audit and sanitize publicly available data, including job posts, websites, and social media. - Use tools like OSINT monitoring platforms (e.g., SpiderFoot, Recon-ng) to identify leaked information. Protect Domain and DNS Infrastructure: - Enable DNSSEC and use WHOIS privacy protection. - Monitor for domain hijacking or lookalike domains using services like RiskIQ or Domain…
MITRE mitigation sourceQuery Public AI Services
Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models (LLMs), to support targeting and operations. In addition to searching websites or databases directly (i.e., [Search Open Websites/Domains](https://attack.mitre.org/techniques/T1593)), adversaries may use AI services to synthesize, aggregate, and analyze publicly available information at scale. This may include identifying individuals or organizations to target, researching organizational structures and personnel, identifying technologies used by target organizations, researching business relationships to develop plausible pretexts for [Social Engineering](https://attack.mitre.org/techniques/T1684) approaches, identifying contact information for use in [Phishing](https://attack.mitre.org/techniques/T1566) or [Phishing for Information](https://attack.mitre.org/techniques/T1598), or gathering derogatory or sensitive information about individuals that may be used for extortion or coercion.(Citation: MSFT-AI)(Citation: GTIG AI Threat Tracker) Information gathered through AI services may be leveraged for other behaviors, such as establishing operational resources (i.e., [Generate Content](https://attack.mitre.org/techniques/T1683) or [Establish Accounts](https://attack.mitre.org/techniques/T1585). For obtaining access to AI tools and services, see [Artificial Intelligence](https://attack.mitre.org/techniques/T1588/007).
Open in the interactive knowledge mesh
Detection overview
Use the published detection strategies below and validate required telemetry in the target environment.
Observed groups
Cyber Knowledge context
Use these routes to move from the ATT&CK behavior into explanation, implementation, evidence handling, validation, and defensive operations. Relevance is generated from explicit identifiers/names and governed topic mappings; it is not attribution evidence.
OSINT & Reconnaissance · topic-match · 81/100Internet exposure, service indexes, and infrastructure search
OSINT & Reconnaissance · topic-match · 81/100Threat infrastructure, IOC enrichment, campaign pivots, and attribution restraint
OSINT & Reconnaissance · topic-match · 81/100Search engines, web archives, public records, and documents
OSINT & Reconnaissance · topic-match · 69/100Public code, packages, cloud artifacts, documents, and exposed secrets
OSINT & Reconnaissance · topic-match · 69/100Module 9 — Tools of the Trade
Cyber Threat Intelligence (CTI) · topic-match · 63/100AI-assisted OSINT with bounded tools, citations, and human review
OSINT & Reconnaissance · topic-match · 60/100Metrics, KRIs, reporting, and maturity without vanity scores
Governance, Risk & Compliance (GRC) · topic-match · 42/100Analysis, confidence, evidence preservation, reporting, and operational handoff
OSINT & Reconnaissance · topic-match · 39/100Authority, ethics, privacy, safety, and operational security
OSINT & Reconnaissance · tactic-route · 24/100Module 4 — Collection Sources
Cyber Threat Intelligence (CTI) · tactic-route · 24/100
MITRE mitigations
MITRE detection strategies and analytics
- AN2062 · Analytic 2062 — Much of this takes place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.