Dynamic Resolution T1568
Tactic: Command & Control
Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control.
Events covered
10 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 37 rules share fields, values, and exclusions.
Fields filtered most (62 distinct)
These fields appear most often in rule filters.
Top indicator values (465 distinct)
These values appear most often in rule predicates.
Exclusions (113 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 6 rules
- Axios NPM Compromise Malicious C2 Domain DNS Query
- Communication To Ngrok Tunneling Service - Linux
- Communication To Ngrok Tunneling Service Initiated
- DNS Resolution Failure Spike
- Download from Suspicious Dyndns Hosts
- macOS DNS Query Tools for C2
Elastic 11 rules
- Cobalt Strike Command and Control Beacon
- Connection to Commonly Abused Web Services
- DNS Request to Suspicious Top Level Domain
- DNS to Commonly Abused Web Services
- Halfbaked Command and Control Beacon
- Machine Learning Detected a DNS Request Predicted to be a DGA Domain
- Machine Learning Detected a DNS Request With a High DGA Probability Score
- Machine Learning Detected DGA activity using a known SUNBURST DNS domain
- Possible FIN7 DGA Command and Control Behavior
- Potential DGA Activity
- Unusual DNS Activity
Kusto 19 rules
- Abnormal Deny Rate for Source IP
- CiscoISE - Device changed IP in last 24 hours
- Corelight - C2 DGA Detected Via Repetitive Failures
- Detect DNS queries reporting multiple errors from different clients - Anomaly Based (ASIM DNS Solution)
- Detect DNS queries reporting multiple errors from different clients - Static threshold based (ASIM DNS Solution)
- Detect excessive NXDOMAIN DNS queries - Anomaly based (ASIM DNS Solution)
- Detect excessive NXDOMAIN DNS queries - Static threshold based (ASIM DNS Solution)
- Excessive NXDOMAIN DNS Queries
- Excessive NXDOMAIN DNS Queries (ASIM DNS Schema)
- Possible contact with a domain generated by a DGA
- Potential communication with a Domain Generation Algorithm (DGA) based hostname (ASIM Web Session schema)
- Potential DGA detected
- Potential DGA detected (ASIM DNS Schema)
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Anomaly based (ASIM DNS Solution)
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Static threshold based (ASIM DNS Solution)
- RecordedFuture Threat Hunting Domain All Actors
- RecordedFuture Threat Hunting IP All Actors
- Tailscale: DNS nameservers modified
- Tailscale: Split-DNS configuration modified