Compliance Node Overview
MITRE ATT&CK T1590.002 (DNS) is an Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's DNS that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target's subdomains, mail servers, and other hosts. DNS MX, TXT, and SPF records may also reveal the use of third party cloud and SaaS providers, such as Office 365, G Suite, Salesforce, or Zendesk. Affected platforms: PRE. MITRE-documented mitigations include M1054 Software Configuration, M1056 Pre-compromise. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CM-06, CM-07, SC-07, SC-32.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1590/002/
SHA-256 integrity: e682fe9716059def69aac45f3990e847c50717601becb39c8d780dde988d92b0
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1590.002: DNS (https://attack.mitre.org/techniques/T1590/002/)
- MITRE ATT&CK Tactic TA0043: Reconnaissance (https://attack.mitre.org/tactics/TA0043/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access