Cross-source coverage

T1568 / ATT&CK

Dynamic Resolution

5957 rules · 5934 families across 5 sources.

5 atomic-IOC hidden · include

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control.

Adversaries may use dynamic resolution for the purpose of Fallback Channels. When contact is lost with the primary command and control server malware may employ dynamic resolution as a means to reestablishing command and control.

Platforms
ESXi · Linux · macOS · Windows
Telemetry
WinEventLog:Sysmonauditd:SYSCALLlinux:syslogmacos:unifiedlogesxi:syslog

How MITRE says to detect it DET0039

Detection Strategy for Dynamic Resolution across OS Platforms

Windows Analytic 0109

Correlate high-frequency or anomalous DNS query activity with processes that do not normally generate network requests (e.g., Office apps, system utilities). Detect pseudo-random or high-entropy domain lookups indicative of domain generation algorithms (DGAs).

  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:Sysmon EventCode=1

Linux Analytic 0110

Monitor /var/log/audit/audit.log and DNS resolver logs for repeated failed lookups or connections to high-entropy domain names. Correlate suspicious DNS queries with process lineage (e.g., Python, bash, or unusual system daemons).

  • auditd:SYSCALL socket/connect
  • linux:syslog Query to suspicious domain with high entropy or low reputation

macOS Analytic 0111

Inspect unified logs for anomalous DNS resolutions triggered by non-network applications. Flag repeated connections to newly registered or algorithmically generated domains. Correlate with endpoint process telemetry.

  • macos:unifiedlog DNS query with pseudo-random subdomain patterns
  • macos:unifiedlog Unexpected applications generating outbound DNS queries

ESXi Analytic 0112

Monitor esxcli and syslog records for DNS resolver changes or repeated queries to unusual external domains by management agents. Detect unauthorized changes to VM or host network settings that redirect DNS lookups.

  • esxi:syslog esxcli network vswitch or DNS resolver configuration updates

Sub-techniques with coverage

Counted in the 5957 above — a rule tagged a sub-technique covers this technique too.


Emerging Threats Open

5940 rules · 5917 families
Detection Severity Format
ET HUNTING WebDAV Traffic to Cloudflare Tunneling Service (.trycloudflare .com) Informational Suricata
ET INFO DYNAMIC_DNS HTTP Request to a *.0000000000000000000000 .com Domain Informational Suricata
ET INFO DYNAMIC_DNS HTTP Request to a *.0000004 .xyz domain Informational Suricata
ET INFO DYNAMIC_DNS HTTP Request to a *.001www .com Domain Informational Suricata
ET INFO DYNAMIC_DNS HTTP Request to a *.03c8 .net Domain Informational Suricata
ET INFO DYNAMIC_DNS HTTP Request to a *.0bit .org Domain Informational Suricata
ET INFO DYNAMIC_DNS HTTP Request to a *.0rg .us Domain Informational Suricata
ET INFO DYNAMIC_DNS HTTP Request to a *.0x .no Domain Informational Suricata
ET INFO DYNAMIC_DNS HTTP Request to a *.100mountain .com Domain Informational Suricata
ET INFO DYNAMIC_DNS HTTP Request to a *.118iranian .com domain Informational Suricata

+ 5930 more from Emerging Threats Open → showing the 10 highest-severity

elastic/detection-rules

10 rules
Detection Severity Format
Cobalt Strike Command and Control Beacon High Elastic TOML
Halfbaked Command and Control Beacon High Elastic TOML
Machine Learning Detected DGA activity using a known SUNBURST DNS domain High Elastic TOML
Possible FIN7 DGA Command and Control Behavior High Elastic TOML
Connection to Commonly Abused Web Services Low Elastic TOML
DNS Request to Suspicious Top Level Domain Low Elastic TOML
Machine Learning Detected a DNS Request Predicted to be a DGA Domain Low Elastic TOML
Machine Learning Detected a DNS Request With a High DGA Probability Score Low Elastic TOML
Potential DGA Activity Low Elastic TOML
Unusual DNS Activity Low Elastic TOML

Azure/Azure-Sentinel

5 rules
Detection Severity Format
Excessive NXDOMAIN DNS Queries (ASIM DNS Schema) Medium KQL
Possible contact with a domain generated by a DGA Medium KQL
Potential communication with a Domain Generation Algorithm (DGA) based hostname (ASIM Web Session schema) Medium KQL
Potential DGA detected (ASIM DNS Schema) Medium KQL
Gentlemen Ransomware C2 domain connection Undefined KQL

SigmaHQ/sigma

1 rule
Detection Severity Format
Download from Suspicious Dyndns Hosts Medium Sigma

chronicle/detection-rules

1 rule
Detection Severity Format
aws_guardduty_dga_domain_activity_detected High YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.