Skip to content
← LibraryTechnique entry
T1583Resource Development

Acquire Infrastructure

Buy / register domains, VPS, CDN accounts, mail servers — staging infrastructure for the operation.

§ Where this technique fits

T1583 is catalogued under the Resource Development tactic of the offensive-security kill-chain. It appears in 15 approved dossiers in the registry, typically at step 1.6 on average.

Authoritative reference: attack.mitre.org/techniques/T1583/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Phishing
    T1566 · Initial Access
    seen 3×
  2. 02
    GitHub / GitLab Dorking
    W-RECON-GITHUB-DORK · Reconnaissance
    seen 2×
  3. 03
    Application Layer Protocol
    T1071 · Command and Control
    seen 1×
  4. 04
    BGP Route Hijack
    NET-BGP-HIJACK · Lateral Movement
    seen 1×
  5. 05seen 1×
  6. 06
    Evil Twin / Rogue AP
    WIFI-EVIL-TWIN · Initial Access
    seen 1×
  7. 07
    Hardware Wallet Supply-Chain Tamper
    WLT-HW-SUPPLY · Initial Access
    seen 1×
  8. 08
    Modify Authentication Process
    T1556 · Credential Access
    seen 1×