// MITRE ATT&CK
T1583 · Acquire Infrastructure
Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting. A wide variety of infrastructure exists for hosting and orchestrating adversary operations. Infrastructure solutions include physical or cloud servers, domains, and third-party web services.(Citation: Trend...
¿Cómo detectarlo y mitigarlo?
La detección de Acquire Infrastructure parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (8)
T1583.001
Domains T1583.002
DNS Server T1583.003
Virtual Private Server T1583.004
Server T1583.005
Botnet T1583.006
Web Services T1583.007
Serverless T1583.008
Malvertising
Domains T1583.002
DNS Server T1583.003
Virtual Private Server T1583.004
Server T1583.005
Botnet T1583.006
Web Services T1583.007
Serverless T1583.008
Malvertising
Técnicas relacionadas
T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates T1587.001
Malware
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates T1587.001
Malware
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.