Compromise Infrastructure T1584

Tactic: Resource Development

Adversaries may compromise third-party infrastructure that can be used during targeting. Infrastructure solutions include physical or cloud servers, domains, network devices, and third-party web and DNS services. Instead of buying, leasing, or renting infrastructure an adversary may compromise infrastructure and use it during other phases of the adversary lifecycle. Additionally, adversaries may compromise numerous machines to form a botnet they can leverage.

Events covered

7 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 12 rules share fields, values, and exclusions.

Fields filtered most (32 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType3eq 2, in 1add unverified domain, disabledomaintransferlock, transferdomaintoanotherawsaccount, verify domain
Provider_Name3eq 3route53domains.amazonaws.com, microsoft-windows-windowsupdateclient
data_stream.dataset3eq 3aws.cloudtrail, azure.auditlogs
event.outcome3eq 3success
Category1eq 1Semperis-DSP-Notifications
EventID1eq 130001
Malware1is_not_null 1
Message1contains 1malware
NewDnsSecState1eq 1OFF
OldDnsSecState1eq 1ON
PreviousRegistrar1is_not_null 1
Registrars1gt 11
ServiceName1eq 1dns.googleapis.com
Severity1eq 1NOTICE
TargetFilename1contains 1, ends_with 1.7z, .bat, .dat

Top indicator values (79 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.outcomeeq
success
3369
Provider_Nameeq
route53domains.amazonaws.com
22
Provider_Nameeq
microsoft-windows-windowsupdateclient
1
data_stream.dataseteq
aws.cloudtrail
2169
Categoryeq
Semperis-DSP-Notifications
1
EventIDeq
30001
1
EventTypeeq
disabledomaintransferlock
1
EventTypeeq
transferdomaintoanotherawsaccount
1
EventTypein
add unverified domain
1
EventTypein
verify domain
1
Messagecontains
malware
1
NewDnsSecStateeq
OFF
1
OldDnsSecStateeq
ON
1
Registrarsgt
1
1
ServiceNameeq
dns.googleapis.com
1
Severityeq
NOTICE
14
TargetFilenamecontains
\appdata\local\temp\tfsstore\tfs_dav\
1
TargetFilenameends_with
.7z
15
TargetFilenameends_with
.bat
117
TargetFilenameends_with
.dat
14
TargetFilenameends_with
.ico
1
TargetFilenameends_with
.js
110
TargetFilenameends_with
.lnk
16
TargetFilenameends_with
.ps1
117
TargetFilenameends_with
.rar
15
TargetFilenameends_with
.vbe
116
TargetFilenameends_with
.vbs
118
TargetFilenameends_with
.zip
17
azure.auditlogs.properties.categoryeq
directorymanagement
12
c-uriends_with
.7z
1

Exclusions (8 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
10.0.0.0/8
1
dest_ipcidr_match
127.0.0.0/8
1
dest_ipcidr_match
169.254.0.0/16
1
dest_ipcidr_match
172.16.0.0/12
1
dest_ipcidr_match
192.168.0.0/16
1
dest_ipcidr_match
::1/128
1
dest_ipcidr_match
fc00::/7
1
dest_ipcidr_match
fe80::/10
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 4 rules

Elastic 3 rules

Kusto 5 rules