T1590.002 · DNS
Sub-technique of T1590 · Gather Victim Network Information.
Adversaries may gather information about the victim's DNS that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target’s subdomains, mail servers, and other hosts. DNS MX, TXT, and SPF...
How to detect & mitigate it
Related techniques
Gather Victim Host Information T1596.003
Digital Certificates T1597.002
Purchase Technical Data T1590.005
IP Addresses T1682
Query Public AI Services T1596.002
WHOIS T1594
Search Victim-Owned Websites T1596.001
DNS/Passive DNS
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.