// MITRE ATT&CK

T1071.004 · DNS

🎯 Command and Control ESXiLinuxmacOSNetwork DevicesWindows Sub-técnica

Sub-técnica de T1071 · Application Layer Protocol.

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client...

¿Cómo detectarlo y mitigarlo?

La detección de DNS parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.

Técnicas relacionadas

Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.