Skip to content

DET0613 Detection of Dynamic Resolution

Item Value
ID DET0613
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T1637 (Dynamic Resolution)

Analytics

Android

AN1667

Monitor for pseudo-randomly generated domain names based on frequency analysis, Markov chains, entropy, proportion of dictionary words, ratio of vowels to other characters, and more.(Citation: Data Driven Security DGA) Additionally, check if the suspicious domain has been recently registered, if it has been rarely visited, or if the domain had a spike in activity after being dormant.(Citation: unit42_strat_aged_domain_det) Content delivery network (CDN) domains may trigger these detections due to the format of their domain names.

Log Sources
Data Component Name Channel
Network Communication (DC0113) Application Vetting None
Mutable Elements
Field Description

iOS

AN1668

Monitor for pseudo-randomly generated domain names based on frequency analysis, Markov chains, entropy, proportion of dictionary words, ratio of vowels to other characters, and more.(Citation: Data Driven Security DGA) Additionally, check if the suspicious domain has been recently registered, if it has been rarely visited, or if the domain had a spike in activity after being dormant.(Citation: unit42_strat_aged_domain_det) Content delivery network (CDN) domains may trigger these detections due to the format of their domain names.

Log Sources
Data Component Name Channel
Network Communication (DC0113) Application Vetting None
Mutable Elements
Field Description