Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Command and Control

T1568.001 Fast Flux DNS

Sub-technique of T1568 Dynamic Resolution

Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name, with multiple IP addresses assigned to it which are swapped with high frequency, using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

SigmaHQ has no rules for this technique.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.