Dangling DNS record — decommissioned subdomain open to takeover
A easy Cloud Infrastructure scenario on Dangling DNS Subdomain Takeover.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.
catalog id · cloud-dangling-dns-subdomain-takeover
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Find and fix a dangling DNS record before a subdomain takeover
- Tie DNS-record lifecycle to resource lifecycle
- Compromise Infrastructure: Domains · Resource DevelopmentT1584.001 · TA0042PartialMedium confidence
Trains defending a subdomain whose dangling DNS record could be claimed to impersonate the brand.
- Resource Access Policy AuditingD3-RAPAMappedHigh confidence
Trains reconciling DNS records against live resource inventory to find dangling entries.
- Network Traffic AnalysisD3-NTAPartialLow confidence
Trains probing the endpoint to confirm whether it is unclaimed or already serving content.
- Asset Management · IdentifyID.AM · IDMappedHigh confidence
Trains inventorying DNS records so orphaned entries are found and retired.
- Continuous Monitoring · DetectDE.CM · DEMappedMedium confidence
Trains detecting dangling records from posture monitoring before they are taken over.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains confirming whether the endpoint is still unclaimed versus already claimed.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains removing or repointing the single stale record without touching the zone.
- Asset Inventory1.AMappedHigh confidence
Trains the asset-inventory baseline that keeps DNS records tied to live resources.
- Detecting Relevant Threats and TTPs3.APartialLow confidence
Trains the detection baseline for subdomain-takeover attempts.
- Secure Configuration of Enterprise Assets and SoftwareControl 4MappedHigh confidence
Trains the configuration hygiene that removes DNS records when their target is deleted.
- Network Monitoring and DefenseControl 13PartialLow confidence
Trains monitoring that surfaces takeover of a trusted subdomain.