Acquire Infrastructure T1583

Tactic: Resource Development

Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting. A wide variety of infrastructure exists for hosting and orchestrating adversary operations. Infrastructure solutions include physical or cloud servers, domains, and third-party web services. Some infrastructure providers offer free trial periods, enabling infrastructure acquisition at limited to no cost. Additionally, botnets are available for rent or purchase.

Authoring guide

These 6 rules share fields, values, and exclusions.

Fields filtered most (13 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType3eq 3associatevpcwithhostedzone, intrusionevent, repo.create
Provider_Name1eq 1route53.amazonaws.com
ScoreDelta1gt 120
TriggerCount1eq 11
asns1is_not_null 1
aws::errorCode1eq 1Client.UnauthorizedOperation
aws::eventName1eq 1RunInstances
data_stream.dataset1eq 1aws.cloudtrail
domainAge1ge 1, lt 10, 7
event.dataset1eq 1github.audit
event.outcome1eq 1success
maxThreatScore1gt 150
sourcetype1eq 1cisco:sfw:estreamer

Top indicator values (15 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
associatevpcwithhostedzone
1
EventTypeeq
intrusionevent
118
EventTypeeq
repo.create
1
Provider_Nameeq
route53.amazonaws.com
1
ScoreDeltagt
20
1
TriggerCounteq
1
1
aws::errorCodeeq
Client.UnauthorizedOperation
1
aws::eventNameeq
RunInstances
12
data_stream.dataseteq
aws.cloudtrail
1169
domainAgege
0
1
domainAgelt
7
1
event.dataseteq
github.audit
114
event.outcomeeq
success
1369
maxThreatScoregt
50
1
sourcetypeeq
cisco:sfw:estreamer
132

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Elastic 2 rules

Splunk 1 rule

Kusto 3 rules