Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1557.001

T1557.001Name Resolution Poisoning and SMB Relay

T1557.001 — Name Resolution Poisoning and SMB Relay is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 5 detection use cases covering it.

Credential AccessCollection
View on the matrix → Filter Detection Library MITRE official spec ↗
5Use cases
0Articles
0Sub-techniques
2Tactics

Use cases covering this technique (5)

Windows Credential Target Information Structure in Commandline ESCU actions · alerting P Windows Kerberos Coercion via DNS ESCU actions · alerting P Windows Short Lived DNS Record ESCU actions · alerting P Windows Theme File Creation in Unusual Location ESCU actions · hunting P DNS Kerberos Coercion ESCU actions · alerting P