+Pre-compromise

Pre-compromise

Pre-compromise mitigations involve proactive measures and defenses implemented to prevent adversaries from successfully identifying and exploiting weaknesses during the Reconnaissance and Resource Development phases of an attack. These activities focus on reducing an organization's attack surface, identify adversarial preparation efforts, and increase the difficulty for attackers to conduct successful operations. This mitigation can be implemented through the following measures: Limit Information Exposure: - Regularly audit and sanitize publicly available data, including job posts, websites, and social media. - Use tools like OSINT monitoring platforms (e.g., SpiderFoot, Recon-ng) to identify leaked information. Protect Domain and DNS Infrastructure: - Enable DNSSEC and use WHOIS privacy protection. - Monitor for domain hijacking or lookalike domains using services like RiskIQ or DomainTools. External Monitoring: - Use tools like Shodan, Censys to monitor your external attack surface. - Deploy external vulnerability scanners to proactively address weaknesses. Threat Intelligence: - Leverage platforms like MISP, Recorded Future, or Anomali to track adversarial infrastructure, tools, and activity. Content and Email Protections: - Use email security solutions like Proofpoint, Microsoft Defender for Office 365, or Mimecast. - Enforce SPF/DKIM/DMARC policies to protect against email spoofing. Training and Awareness: - Educate employees on identifying phishing attempts, securing their social media, and avoiding information leaks.

1. Übersicht

Bezeichnung Standard

1.1 Referenzen

1.2 Identifizierte Anforderungen

1.3 Related Regulations

2. Identifizierte Anforderungen

Anforderungen
Source Anforderung

3. Related Regulations

Regulations
Source Regulierung

Linked Issues

Issuelinks
Linktyp Issue
is related to Mitigations
blocks Active Scanning
blocks Gather Victim Org Information
blocks Cloud Accounts
blocks Vulnerabilities
blocks Artificial Intelligence
blocks Digital Certificates
blocks DNS Server
blocks Server
blocks Audio-Visual Content
blocks Code Signing Certificates
blocks Network Security Appliances
blocks Network Trust Dependencies
blocks DNS/Passive DNS
blocks Develop Capabilities
blocks Server
blocks Credentials
blocks Software
blocks Tool
blocks Domains
blocks Wordlist Scanning
blocks Generate Content
blocks Serverless
blocks Identify Business Tempo
blocks Written Content
blocks Code Signing Certificates
blocks Gather Victim Identity Information
blocks Search Open Technical Databases
blocks Establish Accounts
blocks IP Addresses
blocks Social Media Accounts
blocks Employee Names
blocks Search Victim-Owned Websites
blocks Query Public AI Services
blocks SEO Poisoning
blocks Digital Certificates
blocks Threat Intel Vendors
blocks Social Media Accounts
blocks Email Addresses
blocks Search Engines
blocks Serverless
blocks Malware
blocks Upload Malware
blocks Email Accounts
blocks Gather Victim Network Information
blocks Search Threat Vendor Data
blocks Drive-by Target
blocks Botnet
blocks CDNs
blocks Search Closed Sources
blocks Determine Physical Locations
blocks Web Services
blocks Botnet
blocks Scanning IP Blocks
blocks Virtual Private Server
blocks Purchase Technical Data
blocks Client Configurations
blocks Gather Victim Host Information
blocks Email Accounts
blocks Vulnerability Scanning
blocks Acquire Infrastructure
blocks Business Relationships
blocks Hardware
blocks DNS Server
blocks Web Services
blocks Network Topology
blocks Cloud Accounts
blocks Domains
blocks Domain Properties
blocks Install Digital Certificate
blocks Virtual Private Server
blocks Exploits
blocks Malware
blocks Compromise Accounts
blocks Obtain Capabilities
blocks Digital Certificates
blocks Firmware
blocks Malvertising
blocks Link Target
blocks WHOIS
blocks Exploits
blocks Stage Capabilities
blocks Network Devices
blocks Identify Roles
blocks Compromise Infrastructure
blocks Scan Databases
blocks Social Media
blocks Acquire Access
blocks Upload Tool
  • MITREATTACK -

    © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. https://attack.mitre.org/

    Terms of Use

    LICENSE

    The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

    "© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation."

    DISCLAIMERS

    MITRE does not claim ATT&CK enumerates all possibilities for the types of actions and behaviors documented as part of its adversary model and framework of techniques. Using the information contained within ATT&CK to address or cover full categories of techniques will not guarantee full defensive coverage as there may be undisclosed techniques or variations on existing techniques not documented by ATT&CK.

    ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

    See our FAQ for more information on how to use and represent the ATT&CK name.

Impressum Deutsch Englisch