Detection of Dynamic Resolution

Technique Detected:  Dynamic Resolution | T1637

ID: DET0613
Domains: Mobile
Analytics: AN1667, AN1668
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1667

Monitor for pseudo-randomly generated domain names based on frequency analysis, Markov chains, entropy, proportion of dictionary words, ratio of vowels to other characters, and more.[1] Additionally, check if the suspicious domain has been recently registered, if it has been rarely visited, or if the domain had a spike in activity after being dormant.[2] Content delivery network (CDN) domains may trigger these detections due to the format of their domain names.

Log Sources
Data Component Name Channel
Network Communication (DC0113) Application Vetting None

AN1668

Monitor for pseudo-randomly generated domain names based on frequency analysis, Markov chains, entropy, proportion of dictionary words, ratio of vowels to other characters, and more.[1] Additionally, check if the suspicious domain has been recently registered, if it has been rarely visited, or if the domain had a spike in activity after being dormant.[2] Content delivery network (CDN) domains may trigger these detections due to the format of their domain names.

Log Sources
Data Component Name Channel
Network Communication (DC0113) Application Vetting None

References