T1590.002 DNS
Adversaries may gather information about the victim’s DNS that can be used during targeting. DNS information may include a variety of details, including registered name servers as well as records that outline addressing for a target’s subdomains, mail servers, and other hosts. DNS MX, TXT, and SPF records may also reveal the use of third party cloud and SaaS providers, such as Office 365, G Suite, Salesforce, or Zendesk.5
Adversaries may gather this information in various ways, such as querying or otherwise collecting details via DNS/Passive DNS. DNS information may also be exposed to adversaries via online or other accessible data sets (ex: Search Open Technical Databases).31 Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Technical Databases, Search Open Websites/Domains, or Active Scanning), establishing operational resources (ex: Acquire Infrastructure or Compromise Infrastructure), and/or initial access (ex: External Remote Services).
Adversaries may also use DNS zone transfer (DNS query type AXFR) to collect all records from a misconfigured DNS server.624
| Item | Value |
|---|---|
| ID | T1590.002 |
| Sub-techniques | T1590.001, T1590.002, T1590.003, T1590.004, T1590.005, T1590.006 |
| Tactics | TA0043 |
| Platforms | PRE |
| Version | 1.2 |
| Created | 02 October 2020 |
| Last Modified | 24 October 2025 |
Mitigations
| ID | Mitigation | Description |
|---|---|---|
| M1054 | Software Configuration | Consider implementing policies for DNS servers, such as Zone Transfer Policies, that enforce a list of validated servers permitted for zone transfers.7 |
References
-
CIRCL Computer Incident Response Center. (n.d.). Passive DNS. Retrieved October 20, 2020. ↩
-
CISA. (2016, September 29). DNS Zone Transfer AXFR Requests May Leak Domain Information. Retrieved June 5, 2024. ↩
-
Hacker Target. (n.d.). DNS Dumpster. Retrieved October 20, 2020. ↩
-
Scanning Alexa’s Top 1M for AXFR. (2015, March 29). Retrieved June 5, 2024. ↩
-
Sean Metcalf. (2019, May 9). Sean Metcalf Twitter. Retrieved September 12, 2024. ↩
-
SecurityTrails. (2018, March 14). Wrong Bind Configuration Exposes the Complete List of Russian TLD’s to the Internet. Retrieved June 5, 2024. ↩
-
Microsoft. (2022). DNS Policies Overview. Retrieved June 6, 2024. ↩