Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is domain-based command and control?

Domain-based command and control uses a domain name to direct compromised software towards current control infrastructure. A DNS lookup is only the first stage: resolution, connection, tasking and execution require separate evidence.

Preserve resolution through time

Retain full queries and answers, timestamps, time-to-live values, resolved addresses, certificates, responsible process and later connections. Historical DNS and malware configuration may show destinations that no longer appear in current resolution.

Domains can rotate rapidly, resolve to several addresses or sit behind cloud and content-delivery services. Preserve fallback domains and any domain-generation logic because they may reveal routes not present in collected traffic.

Attribute the right layer

Registration details may be false, privacy-protected, reseller-held or compromised. A domain can also serve websites, APIs or redirection unrelated to control, so process and request context matter.

Where evidence is time-sensitive, preserve provider data promptly. Report what the device resolved and contacted before considering who registered or operated the infrastructure.

Key takeaway

Reconstruct domain-based control from historical DNS through connection and local effect; neither a lookup nor registrant record proves successful control or operator identity.

Reference: CIM-147Cyber Incidents & Offender Methods