triw0lf / HEARTH

A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters to share knowledge, collaborate on techniques, and advance the field of threat hunting.
https://threathuntingcommunity.com/
145 stars 11 forks source link

Dictionary DGA detection via Supervised Classification #10

Closed fetterm4n closed 2 days ago

fetterm4n commented 1 week ago

Hunt Type 🔥

{"Alchemy (Model-Assisted)"=>"Hunts driven by models like anomaly detection or machine learning."}

HEARTH Crafter

fetterm4n

Hunt Idea / Hypothesis

Dictionary-based DGAs are a rare threat that require a model-based approach. These domains are algorithmically generated based on a dictionary of source words. Like traditional Domain Generation Algorithms, machine learning models can distinguish DGA / Non-DGA domains by training on sample data to learn on lexical features separating the classes.

MITRE ATT&CK Tactic

Command and Control

Implementation Notes

Search Tags

CommandandControl, #T1568.002, #DGA

Value and Impact

Knowledge Base

DrTerdnugget commented 2 days ago

Submission approved! Nice work! Don't forget to make a pull request to add your name to the list to get your official Contributor status on the repo here: https://github.com/triw0lf/HEARTH/blob/main/Keepers/Contributors.md