{"id":"T1568","name":"Dynamic Resolution","url":"https://attack.mitre.org/techniques/T1568","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0039","stix_id":"x-mitre-detection-strategy--98d6523f-54c5-4a24-a758-333caa833967","name":"Detection Strategy for Dynamic Resolution across OS Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0039","analytics":[{"id":"AN0109","stix_id":"x-mitre-analytic--7cf1b4ad-95e8-4bf0-8b2f-fc3c14938656","name":"Analytic 0109","description":"Correlate high-frequency or anomalous DNS query activity with processes that do not normally generate network requests (e.g., Office apps, system utilities). Detect pseudo-random or high-entropy domain lookups indicative of domain generation algorithms (DGAs).","url":"https://attack.mitre.org/detectionstrategies/DET0039#AN0109","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"EntropyThreshold","description":"Adjust based on environment to differentiate DGAs from legitimate CDNs"},{"field":"TimeWindow","description":"Interval for correlating bursts of DNS queries from the same process"}],"live":true,"detection_strategies":["DET0039"],"techniques":["T1568"]},{"id":"AN0110","stix_id":"x-mitre-analytic--00112bcc-174f-4201-ac81-fe3edd1292e6","name":"Analytic 0110","description":"Monitor /var/log/audit/audit.log and DNS resolver logs for repeated failed lookups or connections to high-entropy domain names. Correlate suspicious DNS queries with process lineage (e.g., Python, bash, or unusual system daemons).","url":"https://attack.mitre.org/detectionstrategies/DET0039#AN0110","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"socket/connect","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Query to suspicious domain with high entropy or low reputation","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"DomainReputationFeed","description":"Whitelist/blacklist tuned with external threat intel sources"},{"field":"ProcessWhitelist","description":"Known safe daemons that frequently query domains"}],"live":true,"detection_strategies":["DET0039"],"techniques":["T1568"]},{"id":"AN0111","stix_id":"x-mitre-analytic--5e225927-bf50-4261-b1ae-d65e803da0b8","name":"Analytic 0111","description":"Inspect unified logs for anomalous DNS resolutions triggered by non-network applications. Flag repeated connections to newly registered or algorithmically generated domains. Correlate with endpoint process telemetry.","url":"https://attack.mitre.org/detectionstrategies/DET0039#AN0111","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"DNS query with pseudo-random subdomain patterns","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Unexpected applications generating outbound DNS queries","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"NewDomainThreshold","description":"Age of domain registration considered suspicious (e.g., < 30 days)"},{"field":"DNSQueryVolume","description":"Number of queries per process per time window"}],"live":true,"detection_strategies":["DET0039"],"techniques":["T1568"]},{"id":"AN0112","stix_id":"x-mitre-analytic--3166927d-91e4-4e08-bfec-abda2783be8c","name":"Analytic 0112","description":"Monitor esxcli and syslog records for DNS resolver changes or repeated queries to unusual external domains by management agents. Detect unauthorized changes to VM or host network settings that redirect DNS lookups.","url":"https://attack.mitre.org/detectionstrategies/DET0039#AN0112","platforms":["ESXi"],"log_source_references":[{"name":"esxi:syslog","channel":"esxcli network vswitch or DNS resolver configuration updates","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-syslog"}],"mutable_elements":[{"field":"ResolverConfigPaths","description":"Expected resolvers or DNS forwarders in ESXi configurations"},{"field":"ExternalDomainWhitelist","description":"Set of trusted external domains expected for ESXi host activity"}],"live":true,"detection_strategies":["DET0039"],"techniques":["T1568"]}],"live":true,"version":"1.0","techniques":["T1568"]}],"sigma_rules":[{"id":"195c1119-ef07-4909-bb12-e66f5e07bf3c","title":"Download from Suspicious Dyndns Hosts","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2017-11-08","modified":"2023-05-18","description":"Detects download of certain file types from hosts with dynamic DNS names (selected list)","references":["https://www.alienvault.com/blogs/security-essentials/dynamic-dns-security-and-potential-threats"],"logsource":{"category":"proxy"},"tags":["attack.command-and-control","attack.t1105","attack.t1568"],"path":"rules/web/proxy_generic/proxy_download_susp_dyndns.yml","techniques":["T1105","T1568"],"cves":[]},{"id":"73e5d24f-493f-4092-bd2f-c72cabda40ee","title":"Axios NPM Compromise Malicious C2 Domain DNS Query","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects DNS queries for the malicious C2 domain associated with the plain-crypto-js/Axios npm package supply chain compromise.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\nThis detection detects endpoints attempting to resolve the attacker's C2 domain (sfrclak.com) used for command and control communication.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09","https://www.huntress.com/blog/supply-chain-compromise-axios-npm-package"],"logsource":{"category":"dns"},"tags":["attack.command-and-control","attack.t1071.001","attack.t1568","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/net_dns_axios_npm_compromise_indicator.yml","techniques":["T1071.001","T1568"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}