Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1568.002: Domain Generation Algorithms (Enterprise Tactic TA0011 - Command and Control)

MITRE ATT&CK T1568.002 (Domain Generation Algorithms) is an Enterprise Command and Control sub-technique of T1568 (Dynamic Resolution). Adversaries may…

What MITRE ATT&CK T1568.002: Domain Generation Algorithms (Enterprise Tactic TA0011 - Command and Control) requires

MITRE ATT&CK T1568.002 (Domain Generation Algorithms) is an Enterprise Command and Control sub-technique of T1568 (Dynamic Resolution). Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains. This has the advantage of making it much harder for defenders to block, track, or take over the command and control channel, as there potentially could be thousands of domains that malware can check for instructions. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CA-07, SC-07, SC-20, SC-21, SC-22, SI-03, SI-04.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1568/002/

SHA-256 integrity: 428fb2d74797f693d769feeb93aee638eb662e958076ff58638c3af6c447eac2

Primary Citations — 7 traced to source

  • MITRE ATT&CK Technique T1568.002: Domain Generation Algorithms (https://attack.mitre.org/techniques/T1568/002/)
  • MITRE ATT&CK Tactic TA0011: Command and Control (https://attack.mitre.org/tactics/TA0011/)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.