incident-response-trainer
Incident response training · Rule-based scoring
DemoCatalogHistoryDashboard
← Back to catalog
Cloud InfrastructureeasyDangling DNS Subdomain TakeoverMedium asset
Scenario

Dangling DNS record — decommissioned subdomain open to takeover

A easy Cloud Infrastructure scenario on Dangling DNS Subdomain Takeover.

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 4 templates in this Track + Difficulty pool.

catalog id · cloud-dangling-dns-subdomain-takeover

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Find and fix a dangling DNS record before a subdomain takeover
  • Tie DNS-record lifecycle to resource lifecycle
MITRE ATT&CKmitre-attack
  • Compromise Infrastructure: Domains · Resource DevelopmentT1584.001 · TA0042
    PartialMedium confidence

    Trains defending a subdomain whose dangling DNS record could be claimed to impersonate the brand.

MITRE D3FENDmitre-d3fend
  • Resource Access Policy AuditingD3-RAPA
    MappedHigh confidence

    Trains reconciling DNS records against live resource inventory to find dangling entries.

  • Network Traffic AnalysisD3-NTA
    PartialLow confidence

    Trains probing the endpoint to confirm whether it is unclaimed or already serving content.

NIST CSF 2.0nist-csf-2
  • Asset Management · IdentifyID.AM · ID
    MappedHigh confidence

    Trains inventorying DNS records so orphaned entries are found and retired.

  • Continuous Monitoring · DetectDE.CM · DE
    MappedMedium confidence

    Trains detecting dangling records from posture monitoring before they are taken over.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseDetection & Analysis
    MappedHigh confidence

    Trains confirming whether the endpoint is still unclaimed versus already claimed.

  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains removing or repointing the single stale record without touching the zone.

CISA Cybersecurity Performance Goalscisa-cpg
  • Asset Inventory1.A
    MappedHigh confidence

    Trains the asset-inventory baseline that keeps DNS records tied to live resources.

  • Detecting Relevant Threats and TTPs3.A
    PartialLow confidence

    Trains the detection baseline for subdomain-takeover attempts.

CIS Controls v8cis-controls
  • Secure Configuration of Enterprise Assets and SoftwareControl 4
    MappedHigh confidence

    Trains the configuration hygiene that removes DNS records when their target is deleted.

  • Network Monitoring and DefenseControl 13
    PartialLow confidence

    Trains monitoring that surfaces takeover of a trusted subdomain.