What it is
everything an attacker builds or acquires before an intrusion starts. Registering a lookalike domain, renting server space for command-and-control, buying or building malware, compromising a legitimate account or a third-party service to use as staging infrastructure, obtaining code-signing certificates. The intrusion's tooling and infrastructure exist before the first packet ever reaches the target.
Why it isn't covered here
this happens entirely on infrastructure the attacker owns or controls, before any contact with the target network. Every range on this platform is a captured victim environment, so it can only ever contain evidence of what happened inside that network. An attacker's own staging server, wherever it lives, was never part of what got captured, and never could be.
Where the visibility actually comes from, in a real SOC
almost entirely outside your own environment. Threat intelligence on newly registered or recently active domains, passive DNS correlating infrastructure across different campaigns, certificate-transparency logs flagging a certificate issued for a lookalike domain, and vendor or ISAC reporting that ties a piece of infrastructure to a known actor. None of it is something your own SIEM will ever show you directly, which is exactly why it's a separate discipline (threat intelligence) rather than something folded into SOC detection work.
The techniques below are indexed for reference so the matrix stays complete. They are not pending write-ups.
- T1583 Acquire Infrastructure (index only)
- T1583.001 Domains (index only)
- T1583.002 DNS Server (index only)
- T1583.003 Virtual Private Server (index only)
- T1583.004 Server (index only)
- T1583.005 Botnet (index only)
- T1583.006 Web Services (index only)
- T1583.007 Serverless (index only)
- T1583.008 Malvertising (index only)
- T1584 Compromise Infrastructure (index only)
- T1584.001 Domains (index only)
- T1584.002 DNS Server (index only)
- T1584.003 Virtual Private Server (index only)
- T1584.004 Server (index only)
- T1584.005 Botnet (index only)
- T1584.006 Web Services (index only)
- T1584.007 Serverless (index only)
- T1584.008 Network Devices (index only)
- T1585 Establish Accounts (index only)
- T1585.001 Social Media Accounts (index only)
- T1585.002 Email Accounts (index only)
- T1585.003 Cloud Accounts (index only)
- T1586 Compromise Accounts (index only)
- T1586.001 Social Media Accounts (index only)
- T1586.002 Email Accounts (index only)
- T1586.003 Cloud Accounts (index only)
- T1587 Develop Capabilities (index only)
- T1587.001 Malware (index only)
- T1587.002 Code Signing Certificates (index only)
- T1587.003 Digital Certificates (index only)
- T1587.004 Exploits (index only)
- T1588 Obtain Capabilities (index only)
- T1588.001 Malware (index only)
- T1588.002 Tool (index only)
- T1588.003 Code Signing Certificates (index only)
- T1588.004 Digital Certificates (index only)
- T1588.005 Exploits (index only)
- T1588.006 Vulnerabilities (index only)
- T1588.007 Artificial Intelligence (index only)
- T1608 Stage Capabilities (index only)
- T1608.001 Upload Malware (index only)
- T1608.002 Upload Tool (index only)
- T1608.003 Install Digital Certificate (index only)
- T1608.004 Drive-by Target (index only)
- T1608.005 Link Target (index only)
- T1608.006 SEO Poisoning (index only)
- T1650 Acquire Access (index only)
- T1683 Generate Content (index only)
- T1683.001 Written Content (index only)
- T1683.002 Audio-Visual Content (index only)