kevmap

TechniquesT1568.001 › AN1333

AN1333 Analytic 1333

macOS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Use unified logs to identify processes issuing repeated DNS queries where the resolved IP addresses change frequently within very short TTL values. Correlate with outbound network traffic to validate C2-like patterns.</p>
Detects
T1568.001 Fast Flux DNS
Part of
DET0485 Detection Strategy for Dynamic Resolution using Fast Flux DNS

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
macos:unifiedlogRapid domain-to-IP resolution changes for same domainDC0078 Network Traffic Flow
macos:unifiedlogUnexpected apps generating frequent DNS queriesDC0032 Process Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
DNSRotationRateRate of IP churn per domain to trigger detection
NewDomainThresholdFlag if domain was registered recently (e.g., < 30 days)