1200KM / detection
T1583.001 Domains — Detection Rules
Detection workspace for T1583.001 Domains: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0892 Detection of Domains
AN2024 Analytic 2024
Monitor logged domain name system (DNS) data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control. Domain registration information is, by design, captured in public registration logs. Consider use of services that may aid in tracking of newly acquired domains, such as WHOIS databases and/or passive DNS. In some cases it may be possible to pivot on known pieces of domain registration information to uncover other infrastructure purchased by the adversary. Consider monitoring for domains created with a similar structure to your own, including under a different TLD. Though various tools and services exist to track, query, and monitor domain name registration information, tracking across multiple DNS infrastructures can require multiple tools/services or more advanced analytics. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control. Monitor queried domain name system (DNS) registry data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1583.001 simulation workspace
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT1 · G0006
- APT28 · G0007
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- Winnti Group · G0044
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- Leviathan · G0065
- MuddyWater · G0069
- APT38 · G0082
- WIRTE · G0090
- TA505 · G0092
- Kimsuky · G0094
- APT-C-36 · G0099
- Silent Librarian · G0122
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- Transparent Tribe · G0134
- IndigoZebra · G0136
- Ferocious Kitten · G0137
- TeamTNT · G0139
- LazyScripter · G0140
- HEXANE · G1001
- BITTER · G1002
- Earth Lusca · G1006
- EXOTIC LILY · G1011
- CURIUM · G1012
- Scattered Spider · G1015
- TA2541 · G1018
- Star Blizzard · G1033
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- Sea Turtle · G1041
- RedEcho · G1042
- APT42 · G1044
- Storm-1811 · G1046
- Contagious Interview · G1052
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.