Umbra Wiki defense defense/D3-DNSTA
Back to wiki

D3-DNSTA — DNS Traffic Analysis

provenance: imported · ATT&CK: T1040 T1071 T1071.004 T1568 T1568.001 T1568.002 T1568.003

D3-DNSTA: DNS Traffic Analysis

MITRE D3FEND countermeasure

What it does

Analysis of domain name metadata, including name and DNS records, to determine whether the domain is likely to resolve to an undesirable host.

Attacks this counters

The chain in this corpus runs CVE → CWE → CAPEC → ATT&CK technique, which ends at what an adversary does. This is the hop after: what stops it.

Source