Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Resource Development/ T1583.001

T1583.001Domains

T1583.001 — Domains is a MITRE ATT&CK technique in the Resource Development tactic. Clankerusecase tracks 19 detection use cases covering it and 19 threat-intel articles citing it.

Resource Development
View on the matrix → Filter Detection Library MITRE official spec ↗
19Use cases
19Articles
0Sub-techniques
1Tactic

Use cases covering this technique (19)

Click on URL whose host doesn't match the sender domain Internal delivery · hunting DS [LLM] Brand-impersonating phishing pages on abused free-hosting platforms (Sniper Dz pattern) Bespoke delivery · hunting DSPDDCS [LLM] DNS/network contact with AudiA6 money-mule registration domains Bespoke c2 · alerting DSΣPDDCS [LLM] Activity involving ommicrosoft.com Cloaked-Ursa Teams typosquat Bespoke delivery · alerting DSΣPDDCS [LLM] World Cup 2026 themed lookalike / typosquat domain resolution by corporate hosts Bespoke delivery · hunting DSΣPDDCS [LLM] BTMOB C2/phishing domain contact — arbsniper.com Bespoke c2 · alerting DSΣPDDCS [LLM] Screening Serpens C2 — DNS/network to UNC1549 infrastructure (Feb-Apr 2026) Bespoke c2 · alerting DSΣPDDCS [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain Bespoke delivery · alerting DSΣPDDCS [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPDD [LLM] PromptSpy / MorganArg Android banker — distribution domain DNS/proxy hits Bespoke delivery · alerting DSΣPDDCS [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Aikido npm phishing: DNS / web request to siemens-energy.icu or siemensergy.icu typosquats Bespoke delivery · alerting DSΣPDDCS [LLM] DNS / outbound connection to npnjs[.]com phishing infrastructure Bespoke delivery · alerting DSΣPDD [LLM] ESET-impersonating typosquat domain contact (InedibleOchotense / Kalambur delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] GhostAction C2 egress to Plesk-hosted exfiltration infrastructure Bespoke c2 · hunting DSΣPDDCS [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) Bespoke delivery · alerting DSΣPDDCS [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect Bespoke c2 · alerting DSΣPDDCS

Articles citing this technique (19)