Esc
Dead Drop Resolver - T1102.001
(ATT&CK® Technique)
Definition
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.