// MITRE ATT&CK
T1583 · Acquire Infrastructure
Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting. A wide variety of infrastructure exists for hosting and orchestrating adversary operations. Infrastructure solutions include physical or cloud servers, domains, and third-party web services.(Citation: Trend...
How to detect & mitigate it
Detecting Acquire Infrastructure starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (8)
T1583.001
Domains T1583.002
DNS Server T1583.003
Virtual Private Server T1583.004
Server T1583.005
Botnet T1583.006
Web Services T1583.007
Serverless T1583.008
Malvertising
Domains T1583.002
DNS Server T1583.003
Virtual Private Server T1583.004
Server T1583.005
Botnet T1583.006
Web Services T1583.007
Serverless T1583.008
Malvertising
Related techniques
T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates T1587.001
Malware
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates T1587.001
Malware
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.