MITRE ATT&CK technique
Dynamic Resolution detection rulesT1568
Dynamic Resolution (T1568) is a MITRE ATT&CK technique in the Command and Control tactic. This page lists the 4 community-maintained Sigma detection rules in the library mapped to T1568 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target linux, windows.
Tactic
Axios NPM Compromise Malicious C2 Domain DNS Query
highDetects DNS queries for the malicious C2 domain associated with the plain-crypto-js/Axios npm package supply chain compromise. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. This detection detects endpoints attempting to resolve the attacker's C2 domain (sfrclak.com) used for command and control communication.
dns
Communication To Ngrok Tunneling Service - Linux
highDetects an executable accessing an ngrok tunneling endpoint, which could be a sign of forbidden exfiltration of data exfiltration by malicious actors
linux · network_connection
Communication To Ngrok Tunneling Service Initiated
highDetects an executable initiating a network connection to "ngrok" tunneling domains. Attackers were seen using this "ngrok" in order to store their second stage payloads and malware. While communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.
windows · network_connection
Download from Suspicious Dyndns Hosts
mediumDetects download of certain file types from hosts with dynamic DNS names (selected list)
proxy