// MITRE ATT&CK
T1584 · Compromise Infrastructure
Adversaries may compromise third-party infrastructure that can be used during targeting. Infrastructure solutions include physical or cloud servers, domains, network devices, and third-party web and DNS services. Instead of buying, leasing, or renting infrastructure an adversary may compromise infra...
¿Cómo detectarlo y mitigarlo?
La detección de Compromise Infrastructure parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (8)
T1584.001
Domains T1584.002
DNS Server T1584.003
Virtual Private Server T1584.004
Server T1584.005
Botnet T1584.006
Web Services T1584.007
Serverless T1584.008
Network Devices
Domains T1584.002
DNS Server T1584.003
Virtual Private Server T1584.004
Server T1584.005
Botnet T1584.006
Web Services T1584.007
Serverless T1584.008
Network Devices
Técnicas relacionadas
T1583
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.