What MITRE ATT&CK T1568.001: Fast Flux DNS (Enterprise Tactic TA0011 - Command and Control) requires
MITRE ATT&CK T1568.001 (Fast Flux DNS) is an Enterprise Command and Control sub-technique of T1568 (Dynamic Resolution). Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name, with multiple IP addresses assigned to it which are swapped with high frequency, using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource record. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CA-07, SC-07, SC-20, SC-21, SC-22, SI-03, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1568/001/
SHA-256 integrity: 89fbd51dac6cc7edbd72fc8cad2dd09849185bff21ae19313030c01494ed06a3
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1568.001: Fast Flux DNS (https://attack.mitre.org/techniques/T1568/001/)
- MITRE ATT&CK Tactic TA0011: Command and Control (https://attack.mitre.org/tactics/TA0011/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1568-001-fast-flux-dns.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1568-001-fast-flux-dns.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1568-001-fast-flux-dns
- Back to registry: Browse all 10,085 compliance nodes