What MITRE ATT&CK T1568: Dynamic Resolution (Enterprise Tactic TA0011 - Command and Control) requires
MITRE ATT&CK T1568 (Dynamic Resolution) is an Enterprise Command and Control technique. Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorithm with the infrastructure the adversary uses to receive the malware's communications. These calculations can be used to dynamically adjust parameters such as the domain name, IP address, or port number the malware uses for command and control. ATT&CK documents 3 sub-techniques: T1568.001 Fast Flux DNS; T1568.002 Domain Generation Algorithms; T1568.003 DNS Calculation. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1031 Network Intrusion Prevention, M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CA-07, SC-07, SC-20, SC-21, SC-22, SI-03, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1568/
SHA-256 integrity: 1c259877e005aa3e8a744f92adc1ae121ec67d349da0b4dcb9342044cea4b6dd
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1568: Dynamic Resolution (https://attack.mitre.org/techniques/T1568/) with 3 sub-techniques
- MITRE ATT&CK Tactic TA0011: Command and Control (https://attack.mitre.org/tactics/TA0011/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access