Compromise Infrastructure T1584
Tactic: Resource Development
Adversaries may compromise third-party infrastructure that can be used during targeting. Infrastructure solutions include physical or cloud servers, domains, network devices, and third-party web and DNS services. Instead of buying, leasing, or renting infrastructure an adversary may compromise infrastructure and use it during other phases of the adversary lifecycle. Additionally, adversaries may compromise numerous machines to form a botnet they can leverage.
Events covered
7 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 12 rules share fields, values, and exclusions.
Fields filtered most (32 distinct)
These fields appear most often in rule filters.
Top indicator values (79 distinct)
These values appear most often in rule predicates.
Exclusions (8 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 4 rules
- Program Executions in Suspicious Folders
- Suspicious External WebDAV Execution
- WebDAV Temporary Local File Creation
- Windows Update Error
Elastic 3 rules
- AWS Route 53 Domain Transfer Lock Disabled
- AWS Route 53 Domain Transferred to Another Account
- Entra ID Custom Domain Added or Verified