Tactic: Command and Control · Platforms: ESXi, Linux, macOS, Network Devices, Windows
Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure. This can be accomplished by identifying and filtering traffic from defensive tools, masking malicious domains to obfuscate the true destination from both automated scanning tools and…
Sigma detection rules (5)
T1665 Hide Infrastructure
title: T1665 Hide Infrastructure
id: c057f95a-12bb-4ab0-912d-8d835497ea9e
description: 'Detects DNS responses (Sysmon EventID 22) returning an unusually high number of distinct resolved IP addresses for a single query, a heuristic for fast-flux/round-robin DNS and other IP-rotation techniques adversaries use to hide C2 infrastructure from static blocklists and takedown. Note: most other infrastructure-hiding sub-behaviors (domain fronting, EDR/scanner traffic filtering, TLS SNI manipulation) are not observable in Windows host telemetry at all; this rule targets only the one sub-behavior -- DNS/IP churn -- that is. Retargeted from a blanket EventID 5156/5157 firewall-log match, which had no infrastructure-hiding signal at all. (Data Component: Network Connection Creation; baseline tier: windows-eventid.) Tune using: SuspiciousDomains, ResponderIPs, AnswerCountThreshold.'
references:
- https://attack.mitre.org/techniques/T1665
author: Shahrukh Khan
date: 2026-04-23
license: MIT
tags:
- attack.command-and-control
- attack.t1665
logsource:
category: dns_query
product: windows
service: sysmon
detection:
selection:
EventID: '22'
selection_high_answer_count:
QueryResults|re: '^(.*;){5,}.*