Cross-source coverage
T1568 / ATT&CK
Dynamic Resolution
5929 rules · 5926 families across 5 sources.
28 deprecated hidden · include 5 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control.
Adversaries may use dynamic resolution for the purpose of Fallback Channels. When contact is lost with the primary command and control server malware may employ dynamic resolution as a means to reestablishing command and control.
- Tactics
- Command and Control
- Platforms
- ESXi · Linux · macOS · Windows
- Telemetry
-
WinEventLog:Sysmonauditd:SYSCALLlinux:syslogmacos:unifiedlogesxi:syslog
How MITRE says to detect it DET0039
Detection Strategy for Dynamic Resolution across OS Platforms
Windows Analytic 0109
Correlate high-frequency or anomalous DNS query activity with processes that do not normally generate network requests (e.g., Office apps, system utilities). Detect pseudo-random or high-entropy domain lookups indicative of domain generation algorithms (DGAs).
WinEventLog:SysmonEventCode=3, 22WinEventLog:SysmonEventCode=1
Linux Analytic 0110
Monitor /var/log/audit/audit.log and DNS resolver logs for repeated failed lookups or connections to high-entropy domain names. Correlate suspicious DNS queries with process lineage (e.g., Python, bash, or unusual system daemons).
auditd:SYSCALLsocket/connectlinux:syslogQuery to suspicious domain with high entropy or low reputation
macOS Analytic 0111
Inspect unified logs for anomalous DNS resolutions triggered by non-network applications. Flag repeated connections to newly registered or algorithmically generated domains. Correlate with endpoint process telemetry.
macos:unifiedlogDNS query with pseudo-random subdomain patternsmacos:unifiedlogUnexpected applications generating outbound DNS queries
ESXi Analytic 0112
Monitor esxcli and syslog records for DNS resolver changes or repeated queries to unusual external domains by management agents. Detect unauthorized changes to VM or host network settings that redirect DNS lookups.
esxi:syslogesxcli network vswitch or DNS resolver configuration updates
Sub-techniques with coverage
Counted in the 5929 above — a rule tagged a sub-technique covers this technique too.
Emerging Threats Open
5912 rules · 5909 families| Detection | Severity | Format |
|---|---|---|
| ET HUNTING WebDAV Traffic to Cloudflare Tunneling Service (.trycloudflare .com) | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.0000000000000000000000 .com Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.0000004 .xyz domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.001www .com Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.03c8 .net Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.0bit .org Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.0rg .us Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.0x .no Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.100mountain .com Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.118iranian .com domain | Informational | Suricata |
+ 5902 more from Emerging Threats Open → showing the 10 highest-severity
elastic/detection-rules
10 rules| Detection | Severity | Format |
|---|---|---|
| Cobalt Strike Command and Control Beacon | High | Elastic TOML |
| Halfbaked Command and Control Beacon | High | Elastic TOML |
| Machine Learning Detected DGA activity using a known SUNBURST DNS domain | High | Elastic TOML |
| Possible FIN7 DGA Command and Control Behavior | High | Elastic TOML |
| Connection to Commonly Abused Web Services | Low | Elastic TOML |
| DNS Request to Suspicious Top Level Domain | Low | Elastic TOML |
| Machine Learning Detected a DNS Request Predicted to be a DGA Domain | Low | Elastic TOML |
| Machine Learning Detected a DNS Request With a High DGA Probability Score | Low | Elastic TOML |
| Potential DGA Activity | Low | Elastic TOML |
| Unusual DNS Activity | Low | Elastic TOML |
Azure/Azure-Sentinel
5 rules| Detection | Severity | Format |
|---|---|---|
| Excessive NXDOMAIN DNS Queries (ASIM DNS Schema) | Medium | KQL |
| Possible contact with a domain generated by a DGA | Medium | KQL |
| Potential communication with a Domain Generation Algorithm (DGA) based hostname (ASIM Web Session schema) | Medium | KQL |
| Potential DGA detected (ASIM DNS Schema) | Medium | KQL |
| Gentlemen Ransomware C2 domain connection | Undefined | KQL |
SigmaHQ/sigma
1 rule| Detection | Severity | Format |
|---|---|---|
| Download from Suspicious Dyndns Hosts | Medium | Sigma |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| aws_guardduty_dga_domain_activity_detected | High | YARA-L |