Skip to content

Hide Navigation Hide TOC

Passive DNS (cc150ad8-ecfa-4340-9aaa-d21165873bd4)

"Domain Name: Passive DNS" captures logged historical and real-time domain name system (DNS) data. This includes records of domain-to-IP address resolutions over time, enabling analysts to track the evolution of domain infrastructure, uncover historical patterns of use, and detect malicious activities tied to domains and their associated IP addresses. Examples:

  • Historical Resolutions
  • Shared IP Usage
  • Temporal Patterns
  • Malicious Domain Clustering
  • Historical Lookback

This data component can be collected through the following measures:

  • Passive DNS Platforms: Use platforms that specialize in passive DNS collection and analysis:
  • Tools: Farsight DNSDB, RiskIQ PassiveTotal, PassiveDNS.
  • Threat Intelligence Feeds: Integrate passive DNS data from commercial or open-source threat intelligence providers.
  • Custom DNS Collectors: Deploy custom tools to capture DNS traffic at the network level for analysis.
  • Cloud DNS Services: Leverage cloud DNS services (e.g., AWS Route 53, Azure DNS) that maintain DNS query logs.
Cluster A Galaxy A Cluster B Galaxy B Level
Passive DNS (cc150ad8-ecfa-4340-9aaa-d21165873bd4) mitre-data-component Compromise Infrastructure - T1584 (7e3beebd-8bfe-4e7b-a892-e44ab06a75f9) Attack Pattern 1
Passive DNS (cc150ad8-ecfa-4340-9aaa-d21165873bd4) mitre-data-component Acquire Infrastructure - T1583 (0458aab9-ad42-4eac-9e22-706a95bafee2) Attack Pattern 1
DNS Server - T1584.002 (c2f59d25-87fe-44aa-8f83-e8e59d077bf5) Attack Pattern Passive DNS (cc150ad8-ecfa-4340-9aaa-d21165873bd4) mitre-data-component 1
Domains - T1583.001 (40f5caa0-4cb7-4117-89fc-d421bb493df3) Attack Pattern Passive DNS (cc150ad8-ecfa-4340-9aaa-d21165873bd4) mitre-data-component 1
Passive DNS (cc150ad8-ecfa-4340-9aaa-d21165873bd4) mitre-data-component Domains - T1584.001 (f9cc4d06-775f-4ee1-b401-4e2cc0da30ba) Attack Pattern 1
DNS Server - T1584.002 (c2f59d25-87fe-44aa-8f83-e8e59d077bf5) Attack Pattern Compromise Infrastructure - T1584 (7e3beebd-8bfe-4e7b-a892-e44ab06a75f9) Attack Pattern 2
Domains - T1583.001 (40f5caa0-4cb7-4117-89fc-d421bb493df3) Attack Pattern Acquire Infrastructure - T1583 (0458aab9-ad42-4eac-9e22-706a95bafee2) Attack Pattern 2
Compromise Infrastructure - T1584 (7e3beebd-8bfe-4e7b-a892-e44ab06a75f9) Attack Pattern Domains - T1584.001 (f9cc4d06-775f-4ee1-b401-4e2cc0da30ba) Attack Pattern 2