// MITRE ATT&CK
T1584 · Compromise Infrastructure
Adversaries may compromise third-party infrastructure that can be used during targeting. Infrastructure solutions include physical or cloud servers, domains, network devices, and third-party web and DNS services. Instead of buying, leasing, or renting infrastructure an adversary may compromise infra...
How to detect & mitigate it
Detecting Compromise Infrastructure starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (8)
T1584.001
Domains T1584.002
DNS Server T1584.003
Virtual Private Server T1584.004
Server T1584.005
Botnet T1584.006
Web Services T1584.007
Serverless T1584.008
Network Devices
Domains T1584.002
DNS Server T1584.003
Virtual Private Server T1584.004
Server T1584.005
Botnet T1584.006
Web Services T1584.007
Serverless T1584.008
Network Devices
Related techniques
T1583
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.