T1584
Compromise Infrastructure
PRE1 piece on this siteT1584 on attack.mitre.org
Adversaries may compromise third-party infrastructure that can be used during targeting. Infrastructure solutions include physical or cloud servers, domains, network devices, and third-party web and DNS services. Instead of buying, leasing, or renting infrastructure an adversary may compromise infrastructure and use it during other phases of the adversary lifecycle.
If this is happening now
Checklists and playbooks to open while the alert is still live.
First-hour playbookMembers
Your DNS records changed and nobody here did it
Mail stops arriving, a site resolves somewhere unexpected, a certificate appears that nobody requested, or the registrar emails about a change nobody made.
T1584.002T1584.001
how MITRE says to see it
Detection of Compromise Infrastructure
- Once adversaries have provisioned compromised infrastructure (ex: a server for use in command and control), internet scans may help proactively discover compromised infrastructure.
what reduces it
- M1056 Pre-compromise. This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.