{"id":"T1568.001","name":"Fast Flux DNS","url":"https://attack.mitre.org/techniques/T1568/001","tactics":["command-and-control"],"platforms":["Linux","macOS","Windows","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0485","stix_id":"x-mitre-detection-strategy--4556646a-39df-48bf-9df3-623d4da7a859","name":"Detection Strategy for Dynamic Resolution using Fast Flux DNS","url":"https://attack.mitre.org/detectionstrategies/DET0485","analytics":[{"id":"AN1331","stix_id":"x-mitre-analytic--7e6e9c0e-737e-43ac-8cdd-5edbff4d6424","name":"Analytic 1331","description":"Identify repeated DNS resolutions where the same domain name returns multiple IPs in short succession, combined with low TTL values and high query volume from unusual processes. Correlate with process lineage (e.g., Office apps spawning abnormal DNS lookups).","url":"https://attack.mitre.org/detectionstrategies/DET0485#AN1331","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"DNSQueryBurstThreshold","description":"Number of unique IPs returned per domain in a short window"},{"field":"TimeWindow","description":"Adjust correlation timeframe for fast flux detection (e.g., 5–10 minutes)"}],"live":true,"detection_strategies":["DET0485"],"techniques":["T1568.001"]},{"id":"AN1332","stix_id":"x-mitre-analytic--8a226737-e2a7-4b70-8964-98c47444a638","name":"Analytic 1332","description":"Monitor resolver logs and auditd events for domains resolving to a rotating set of IPs within very short TTL intervals. Correlate high query rates from non-browser applications (e.g., python, curl).","url":"https://attack.mitre.org/detectionstrategies/DET0485#AN1332","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"socket/connect","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"TTLThreshold","description":"Minimum TTL value considered suspicious (e.g., < 60 seconds)"},{"field":"DomainReputationFeed","description":"External TI feed to exclude benign CDN or load balancer behavior"}],"live":true,"detection_strategies":["DET0485"],"techniques":["T1568.001"]},{"id":"AN1333","stix_id":"x-mitre-analytic--22d28e80-ecae-4fa4-8901-ef9125c99e9f","name":"Analytic 1333","description":"Use unified logs to identify processes issuing repeated DNS queries where the resolved IP addresses change frequently within very short TTL values. Correlate with outbound network traffic to validate C2-like patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0485#AN1333","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Rapid domain-to-IP resolution changes for same domain","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Unexpected apps generating frequent DNS queries","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"DNSRotationRate","description":"Rate of IP churn per domain to trigger detection"},{"field":"NewDomainThreshold","description":"Flag if domain was registered recently (e.g., < 30 days)"}],"live":true,"detection_strategies":["DET0485"],"techniques":["T1568.001"]},{"id":"AN1334","stix_id":"x-mitre-analytic--f9534b4a-57ef-40a0-801a-d56a217304f0","name":"Analytic 1334","description":"Monitor ESXi syslog and esxcli outputs for abnormal DNS resolver behavior, such as frequent domain-to-IP changes or unauthorized modifications of DNS settings used by management agents. Correlate domain lookups with short TTL values.","url":"https://attack.mitre.org/detectionstrategies/DET0485#AN1334","platforms":["ESXi"],"log_source_references":[{"name":"esxi:syslog","channel":"Frequent DNS resolution of same domain with rotating IPs","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-syslog"}],"mutable_elements":[{"field":"ResolverConfigPaths","description":"Whitelist of expected DNS resolvers configured on ESXi"},{"field":"ExternalDomainWhitelist","description":"Known trusted external domains for hypervisor services"}],"live":true,"detection_strategies":["DET0485"],"techniques":["T1568.001"]}],"live":true,"version":"1.0","techniques":["T1568.001"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}