Closed fetterm4n closed 2 days ago
Submission approved! Nice work! Don't forget to make a pull request to add your name to the list to get your official Contributor status on the repo here: https://github.com/triw0lf/HEARTH/blob/main/Keepers/Contributors.md
Hunt Type 🔥
{"Alchemy (Model-Assisted)"=>"Hunts driven by models like anomaly detection or machine learning."}
HEARTH Crafter
fetterm4n
Hunt Idea / Hypothesis
Dictionary-based DGAs are a rare threat that require a model-based approach. These domains are algorithmically generated based on a dictionary of source words. Like traditional Domain Generation Algorithms, machine learning models can distinguish DGA / Non-DGA domains by training on sample data to learn on lexical features separating the classes.
MITRE ATT&CK Tactic
Command and Control
Implementation Notes
Search Tags
CommandandControl, #T1568.002, #DGA
Value and Impact
Knowledge Base