DNS

T1590.002

Sub-technique of T1590 Gather Victim Network Information.View on attack.mitre.org

About this technique

Adversaries may gather information about the victim's DNS that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target’s subdomains, mail servers, and other hosts. DNS MX, TXT, and SPF records may also reveal the use of third party cloud and SaaS providers, such as Office 365, G Suite, Salesforce, or Zendesk.

Adversaries may gather this information in various ways, such as querying or otherwise collecting details via DNS/Passive DNS. DNS information may also be exposed to adversaries via online or other accessible data sets (ex: Search Open Technical Databases). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Technical Databases, Search Open Websites/Domains, or Active Scanning), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services).

Adversaries may also use DNS zone transfer (DNS query type AXFR) to collect all records from a misconfigured DNS server.

Detection rules2

Rules on DetectionCode tagged with T1590.002.

Sigma1

RuleLevelLog source
Failed DNS Zone Transfermediumwindows / NULL

Splunk1

RuleTypeRiskData source
Windows DNS Gather Network InfoAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References6

  1. Alexa-dns Open source
    Scanning Alexa's Top 1M for AXFR. (2015, March 29). Retrieved June 5, 2024.
  2. Circl Passive DNS Open source
    CIRCL Computer Incident Response Center. (n.d.). Passive DNS. Retrieved October 20, 2020.
  3. DNS Dumpster Open source
    Hacker Target. (n.d.). DNS Dumpster. Retrieved October 20, 2020.
  4. DNS-CISA Open source
    CISA. (2016, September 29). DNS Zone Transfer AXFR Requests May Leak Domain Information. Retrieved June 5, 2024.
  5. Sean Metcalf Twitter DNS Records Open source
    Sean Metcalf. (2019, May 9). Sean Metcalf Twitter. Retrieved September 12, 2024.
  6. Trails-DNS Open source
    SecurityTrails. (2018, March 14). Wrong Bind Configuration Exposes the Complete List of Russian TLD's to the Internet. Retrieved June 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.