1200KM / detection
T1637.001 Domain Generation Algorithms — Detection Rules
Detection workspace for T1637.001 Domain Generation Algorithms: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0669 Detection of Domain Generation Algorithms
AN1765 Analytic 1765
Monitor for pseudo-randomly generated domain names based on frequency analysis, Markov chains, entropy, proportion of dictionary words, ratio of vowels to other characters, and more. Additionally, check if the suspicious domain has been recently registered, if it has been rarely visited, or if the domain had a spike in activity after being dormant. Content delivery network (CDN) domains may trigger these detections due to the format of their domain names.
AN1766 Analytic 1766
Monitor for pseudo-randomly generated domain names based on frequency analysis, Markov chains, entropy, proportion of dictionary words, ratio of vowels to other characters, and more. Additionally, check if the suspicious domain has been recently registered, if it has been rarely visited, or if the domain had a spike in activity after being dormant. Content delivery network (CDN) domains may trigger these detections due to the format of their domain names.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1637.001 simulation workspace
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.