Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Resource Development/ T1583.001

T1583.001Domains

T1583.001 — Domains is a MITRE ATT&CK technique in the Resource Development tactic. Clankerusecase tracks 13 detection use cases covering it and 12 threat-intel articles citing it.

Resource Development
View on the matrix → Filter Detection Library MITRE official spec ↗
13Use cases
12Articles
0Sub-techniques
1Tactic

Use cases covering this technique (13)

Click on URL whose host doesn't match the sender domain Internal delivery · hunting DS [LLM] Endpoint contact with F6 fraud-campaign hosting infra (212.127.73.235 / 167.86.100.68) Bespoke delivery · hunting DSΣPDDCS [LLM] DNS / web resolution of F6 counterfeit Russian-company domains Bespoke delivery · alerting DSΣPDDCS [LLM] AI coding-assistant egress to first-seen external domain (phantom squatting) Bespoke c2 · hunting DSPDDCS [LLM] BTMOB C2/phishing domain contact — arbsniper.com Bespoke c2 · alerting DSΣPDDCS [LLM] Mail-borne click to fake FIFA World Cup 2026 phishing domain Bespoke delivery · alerting DSΣPDDCS [LLM] FrostyNeighbor C2 callout to needbinding/nebao/algsat/sardk/alexavegas/lavanille Bespoke c2 · alerting DSΣPDDCS [LLM] TeamPCP Trivy/KICS C2 callback to scan.aquasecurtiy.org / 45.148.10.212 Bespoke c2 · hunting DSΣPDD [LLM] Trivy supply-chain C2 beacon to typosquat domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPDD [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) Bespoke c2 · alerting DSΣPDDCS [LLM] ESET-impersonating typosquat domain contact (InedibleOchotense / Kalambur delivery) Bespoke delivery · alerting DSΣPDDCS [LLM] npm registry typosquat npnjs.com — DNS / URL click (eslint-config-prettier maintainer phishing kit) Bespoke delivery · alerting DSΣPDDCS [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect Bespoke c2 · alerting DSΣPDDCS

Articles citing this technique (12)