Esc
Fast Flux DNS - T1568.001
(ATT&CK® Technique)
Definition
Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name, with multiple IP addresses assigned to it which are swapped with high frequency, using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource record.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.