Skip to content

DET0669 Detection of Domain Generation Algorithms

Item Value
ID DET0669
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T1637.001 (Domain Generation Algorithms)

Analytics

Android

AN1765

Monitor for pseudo-randomly generated domain names based on frequency analysis, Markov chains, entropy, proportion of dictionary words, ratio of vowels to other characters, and more.(Citation: Data Driven Security DGA) Additionally, check if the suspicious domain has been recently registered, if it has been rarely visited, or if the domain had a spike in activity after being dormant.(Citation: unit42_strat_aged_domain_det) Content delivery network (CDN) domains may trigger these detections due to the format of their domain names.

Log Sources
Data Component Name Channel
Network Communication (DC0113) Application Vetting None
Mutable Elements
Field Description

iOS

AN1766

Monitor for pseudo-randomly generated domain names based on frequency analysis, Markov chains, entropy, proportion of dictionary words, ratio of vowels to other characters, and more.(Citation: Data Driven Security DGA) Additionally, check if the suspicious domain has been recently registered, if it has been rarely visited, or if the domain had a spike in activity after being dormant.(Citation: unit42_strat_aged_domain_det) Content delivery network (CDN) domains may trigger these detections due to the format of their domain names.

Log Sources
Data Component Name Channel
Network Communication (DC0113) Application Vetting None
Mutable Elements
Field Description