Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Resource Development/ T1583.001

T1583.001Domains

T1583.001 — Domains is a MITRE ATT&CK technique in the Resource Development tactic. Clankerusecase tracks 11 detection use cases covering it and 11 threat-intel articles citing it.

Resource Development
View on the matrix → Filter Detection Library MITRE official spec ↗
11Use cases
11Articles
0Sub-techniques
1Tactic

Use cases covering this technique (11)

Click on URL whose host doesn't match the sender domain Internal delivery · hunting DS [LLM] Endpoint callback to Sable Squirrel dropcatch C2 domains (Quasar RAT via cel-robox[.]com) Bespoke c2 · alerting DSΣPDDCS [LLM] Armored Likho Still Toolkit C2 infrastructure IOC match (domains + IPs) Bespoke c2 · hunting DSΣPDDCS [LLM] BTMOB C2/phishing domain contact — arbsniper.com Bespoke c2 · alerting DSΣPDDCS [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain Bespoke delivery · alerting DSΣPDDCS [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPDD [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) Bespoke c2 · alerting DSΣPDDCS [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) Bespoke delivery · alerting DSΣPDDCS [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect Bespoke c2 · alerting DSΣPDDCS

Articles citing this technique (11)