What MITRE ATT&CK T1596.001: DNS/Passive DNS (Enterprise Tactic TA0043 - Reconnaissance) requires
MITRE ATT&CK T1596.001 (DNS/Passive DNS) is an Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search DNS data for information about victims that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target's subdomains, mail servers, and other hosts. Adversaries may search DNS data to gather actionable information. Threat actors can query nameservers for a target organization directly, or search through centralized repositories of logged DNS query responses (known as passive DNS). Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1596/001/
SHA-256 integrity: 93fff6892a6f17d061358af70e91b19b819bf4e33f64f623b8f89950e7be7fd2
Primary Citations — 5 traced to source
- MITRE ATT&CK Technique T1596.001: DNS/Passive DNS (https://attack.mitre.org/techniques/T1596/001/)
- MITRE ATT&CK Tactic TA0043: Reconnaissance (https://attack.mitre.org/tactics/TA0043/)
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.