{
  "node_id": "mitre-attack-t1102-001-dead-drop-resolver",
  "title": "MITRE ATT&CK T1102.001: Dead Drop Resolver (Enterprise Tactic TA0011 - Command and Control)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1102.001 (Dead Drop Resolver) is an Enterprise Command and Control sub-technique of T1102 (Web Service). Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CA-07, CM-02, CM-06, CM-07, SC-07, SI-03, SI-04.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-t1102-web-service"
  ],
  "primary_citations_count": 7
}