What MITRE ATT&CK T1584.002: DNS Server (Enterprise Tactic TA0042 - Resource Development) requires
MITRE ATT&CK T1584.002 (DNS Server) is an Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise third-party DNS servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS traffic for various tasks, including for Command and Control (ex: Application Layer Protocol). Instead of setting up their own DNS servers, adversaries may compromise third-party DNS servers in support of operations. By compromising DNS servers, adversaries can alter DNS records. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1584/002/
SHA-256 integrity: 3d687807a0516d76972e6d45eb1da05c9acc0ad4d1fcdf4509fae16e3735e048
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1584.002: DNS Server (https://attack.mitre.org/techniques/T1584/002/)
- MITRE ATT&CK Tactic TA0042: Resource Development (https://attack.mitre.org/tactics/TA0042/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.