Built adversary-in-the-middle DNS servers to impersonate legitimate services that were later used to capture credentials.12
- Tactic
- Resource Development
- Platform
- PRE
- Version
- 1.0
- Created
- 01 October 2020
- Last modified
- 24 October 2025
Adversaries may set up their own Domain Name System (DNS) servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS traffic for various tasks, including for Command and Control (ex: Application Layer Protocol). Instead of hijacking existing DNS servers, adversaries may opt to configure and run their own DNS servers in support of operations.
DNS Server MITRE reference T1583.002
3 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has set up custom DNS servers to send commands to compromised hosts via TXT records.1
Has acquired dynamic DNS services for use in the targeting of intended victims.1
All 3 groups for this technique
Offense vs defense T1583.002
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
DNS Server detection strategy DET0862
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of DNS Server
AN1994 · PRE
Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.