Skip to content
COOEY

◄ SIGNAL FUSION

ATT&CK MATRIX

Reference · MITRE

The full MITRE ATT&CK Enterprise kill chain — every tactic column and technique cell, collected fresh from MITRE's public STIX. Cell intensity = how many tracked threat groups use the technique; = cited in advisories we collect. Click a technique for detail; filter by group to see one actor's playbook.

MATRIX_DOMAIN ENTERPRISE MOBILE ICS ⇩ EXPORT_JSON
TECHNIQUE · T1071.004 — DNS
command and control ESXiLinuxmacOSNetwork DevicesWindows SUB-TECHNIQUE of T1071 MITRE page ↗

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control withi…

Threat groups using it · 11
Reconnaissance
TA0043 · 12
Resource Development
TA0042 · 9
Initial Access
TA0001 · 11
Execution
TA0002 · 20
Persistence
TA0003 · 22
Privilege Escalation
TA0004 · 13
Stealth
TA0005 · 30
Defense Impairment
TA0112 · 18
Credential Access
TA0006 · 17
Discovery
TA0007 · 34
Lateral Movement
TA0008 · 9
Collection
TA0009 · 17
Command and Control
TA0011 · 18
Exfiltration
TA0010 · 9
Impact
TA0040 · 15
Heat · group adoption: ≤ median > median top quartile top decile ◆ n = cited in n of our collected advisories Source: MITRE ATT&CK Enterprise · attack-stix-data · group adoption = STIX “uses” edges