Compliance Node Overview
MITRE ATT&CK T1102.001 (Dead Drop Resolver) is an Enterprise Command and Control sub-technique of T1102 (Web Service). Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1021 Restrict Web-Based Content, M1031 Network Intrusion Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CA-07, CM-02, CM-06, CM-07, SC-07, SI-03, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1102/001/
SHA-256 integrity: 101ddea2fa9f9c5248641f5df0d49bb36f3c91ac7dc77c811fa5d1bfd367201c
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1102.001: Dead Drop Resolver (https://attack.mitre.org/techniques/T1102/001/)
- MITRE ATT&CK Tactic TA0011: Command and Control (https://attack.mitre.org/tactics/TA0011/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access