Dynamic Resolution T1568

Tactic: Command & Control

Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control.

Events covered

10 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 37 rules share fields, values, and exclusions.

Fields filtered most (62 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
QueryName5is_not_null 3, contains 2, wildcard 2, ends_with 1., *.2miners.com, *.4shared.com, *.antpool.com, *.blob.core.windows.net
count_5gt 51, 200, 25
DestinationHostname4contains 2, regex_match 2, ne 1tunnel.ap.ngrok.com, tunnel.au.ngrok.com, tunnel.eu.ngrok.com, [a-z]{3}\.stage\.[0-9]{8}\..*, [a-za-z]{4,5}\.(pw|us|club|info|site|top)
Action3eq 3UPDATE, Deny
DestinationPortName3in 2, eq 1http, tls
EventResultDetails_s3eq 2, in 1NXDOMAIN, REFUSED, SERVFAIL
EventTime_t3cross_field_compare 3min_t
Name3contains 3.
TimeGenerated3cross_field_compare 2, ge 1, le 1maxSummarizedTime, FullWindowEnd, FullWindowStart
data_stream.dataset3in 3network_traffic.http, network_traffic.tls
event.category3in 3network, network_traffic
host.os.type3eq 3
process_name3is_not_null 3
score3ge 35
DGADomain2gt 2, regex_match 28, ^[A-Za-z]{0,}$

Top indicator values (465 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTime_tcross_field_compare
min_t
34
Namecontains
.
37
data_stream.datasetin
network_traffic.http
35
data_stream.datasetin
network_traffic.tls
34
event.categoryin
network
318
event.categoryin
network_traffic
316
scorege
5
36
Actioneq
UPDATE
24
DGADomaingt
8
22
DGADomainregex_match
^[A-Za-z]{0,}$
22
DestinationHostnamecontains
tunnel.ap.ngrok.com
22
DestinationHostnamecontains
tunnel.au.ngrok.com
22
DestinationHostnamecontains
tunnel.eu.ngrok.com
22
DestinationHostnamecontains
tunnel.in.ngrok.com
22
DestinationHostnamecontains
tunnel.jp.ngrok.com
22
DestinationHostnamecontains
tunnel.sa.ngrok.com
22
DestinationHostnamecontains
tunnel.us.ngrok.com
22
DestinationPortNamein
http
22
DestinationPortNamein
tls
22
DnsQueryTypeNamein
A
22
DnsQueryTypeNamein
AAAA
22
EventResultDetails_seq
NXDOMAIN
22
IsActiveeq
true
221
Protocoleq
tcp
226
QueryNamecontains
.
27
QueryNamewildcard
*.blob.core.windows.net
22
QueryNamewildcard
*.blob.storage.azure.net
22
QueryNamewildcard
*.blogspot.com
24
QueryNamewildcard
*.cloud.es.io
22
QueryNamewildcard
*.devtunnels.ms
22

Exclusions (113 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Namecontains
.
3
DGADomaingt
8
2
DGADomainregex_match
^[A-Za-z]{0,}$
2
Nameends_with
.home
2
Nameends_with
.lan
2
QueryNamecontains
/
2
SourceIpcidr_match
127.0.0.1
2
count_gt
1
2
dcount_sldgt
100
2
triCountgt
500
2
ClientIPcidr_match
127.0.0.1
1
DNSQueryCountgt
100
1
Imagewildcard
/opt/elastic/agent/data/elastic-agent-*/components/elastic-otel-collector
1
Imagewildcard
/opt/google-cloud-ops-agent/subagents/fluent-bit/bin/fluent-bit
1
Imagewildcard
/opt/google-cloud-ops-agent/subagents/opentelemetry-collector/otelopscol
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 6 rules

Elastic 11 rules

Kusto 19 rules

YARA-L 1 rule