Dynamic Resolution: Fast Flux DNS T1568.001

Tactic: Command & Control

Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name, with multiple IP addresses assigned to it which are swapped with high frequency, using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource record.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (7 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Action1eq 1Deny
AlertTimeSrcIpDenyRateCount1cross_field_compare 1LearningThreshold
Fqdn1is_not_null 1
LearningTimeBuckets1gt 15
OperationName1eq 1AzureFirewallApplicationRuleLog, AzureFirewallNetworkRuleLog
TimeGenerated1ge 1, le 1FullWindowEnd, FullWindowStart
src_ip1is_not_null 1

Top indicator values (7 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
Actioneq
Deny
12
AlertTimeSrcIpDenyRateCountcross_field_compare
LearningThreshold
12
LearningTimeBucketsgt
5
12
OperationNameeq
AzureFirewallApplicationRuleLog
14
OperationNameeq
AzureFirewallNetworkRuleLog
13
TimeGeneratedge
FullWindowStart
1
TimeGeneratedle
FullWindowEnd
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Azure

Domain: Cloud

Kusto 1 rule