Cross-source coverage
T1568 / ATT&CK
Dynamic Resolution
5957 rules · 5934 families across 5 sources.
5 atomic-IOC hidden · include
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control.
Adversaries may use dynamic resolution for the purpose of Fallback Channels. When contact is lost with the primary command and control server malware may employ dynamic resolution as a means to reestablishing command and control.
- Tactics
- Command and Control
- Platforms
- ESXi · Linux · macOS · Windows
- Telemetry
-
WinEventLog:Sysmonauditd:SYSCALLlinux:syslogmacos:unifiedlogesxi:syslog
How MITRE says to detect it DET0039
Detection Strategy for Dynamic Resolution across OS Platforms
Windows Analytic 0109
Correlate high-frequency or anomalous DNS query activity with processes that do not normally generate network requests (e.g., Office apps, system utilities). Detect pseudo-random or high-entropy domain lookups indicative of domain generation algorithms (DGAs).
WinEventLog:SysmonEventCode=3, 22WinEventLog:SysmonEventCode=1
Linux Analytic 0110
Monitor /var/log/audit/audit.log and DNS resolver logs for repeated failed lookups or connections to high-entropy domain names. Correlate suspicious DNS queries with process lineage (e.g., Python, bash, or unusual system daemons).
auditd:SYSCALLsocket/connectlinux:syslogQuery to suspicious domain with high entropy or low reputation
macOS Analytic 0111
Inspect unified logs for anomalous DNS resolutions triggered by non-network applications. Flag repeated connections to newly registered or algorithmically generated domains. Correlate with endpoint process telemetry.
macos:unifiedlogDNS query with pseudo-random subdomain patternsmacos:unifiedlogUnexpected applications generating outbound DNS queries
ESXi Analytic 0112
Monitor esxcli and syslog records for DNS resolver changes or repeated queries to unusual external domains by management agents. Detect unauthorized changes to VM or host network settings that redirect DNS lookups.
esxi:syslogesxcli network vswitch or DNS resolver configuration updates
Sub-techniques with coverage
Counted in the 5957 above — a rule tagged a sub-technique covers this technique too.
Emerging Threats Open
5940 rules · 5917 families| Detection | Severity | Format |
|---|---|---|
| ET HUNTING WebDAV Traffic to Cloudflare Tunneling Service (.trycloudflare .com) | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.0000000000000000000000 .com Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.0000004 .xyz domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.001www .com Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.03c8 .net Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.0bit .org Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.0rg .us Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.0x .no Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.100mountain .com Domain | Informational | Suricata |
| ET INFO DYNAMIC_DNS HTTP Request to a *.118iranian .com domain | Informational | Suricata |
+ 5930 more from Emerging Threats Open → showing the 10 highest-severity
elastic/detection-rules
10 rules| Detection | Severity | Format |
|---|---|---|
| Cobalt Strike Command and Control Beacon | High | Elastic TOML |
| Halfbaked Command and Control Beacon | High | Elastic TOML |
| Machine Learning Detected DGA activity using a known SUNBURST DNS domain | High | Elastic TOML |
| Possible FIN7 DGA Command and Control Behavior | High | Elastic TOML |
| Connection to Commonly Abused Web Services | Low | Elastic TOML |
| DNS Request to Suspicious Top Level Domain | Low | Elastic TOML |
| Machine Learning Detected a DNS Request Predicted to be a DGA Domain | Low | Elastic TOML |
| Machine Learning Detected a DNS Request With a High DGA Probability Score | Low | Elastic TOML |
| Potential DGA Activity | Low | Elastic TOML |
| Unusual DNS Activity | Low | Elastic TOML |
Azure/Azure-Sentinel
5 rules| Detection | Severity | Format |
|---|---|---|
| Excessive NXDOMAIN DNS Queries (ASIM DNS Schema) | Medium | KQL |
| Possible contact with a domain generated by a DGA | Medium | KQL |
| Potential communication with a Domain Generation Algorithm (DGA) based hostname (ASIM Web Session schema) | Medium | KQL |
| Potential DGA detected (ASIM DNS Schema) | Medium | KQL |
| Gentlemen Ransomware C2 domain connection | Undefined | KQL |
SigmaHQ/sigma
1 rule| Detection | Severity | Format |
|---|---|---|
| Download from Suspicious Dyndns Hosts | Medium | Sigma |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| aws_guardduty_dga_domain_activity_detected | High | YARA-L |