Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a dead-drop resolver?

A dead-drop resolver is public content that tells malicious software where to find its current control infrastructure. The hosting service is a directory step, not necessarily the command channel itself.

Reconstruct the two-stage route

The location might be a social profile, repository, paste, document, blockchain entry or cloud object. Preserve the precise content, stable object and account IDs, publication and modification history, access records and the process retrieving it.

Then show what address or domain the content revealed and whether the process contacted it. Retrieval does not prove the second connection succeeded.

Preserve more than appearance

Public content can change or disappear quickly. Native exports and version history retain metadata that a screenshot lacks. Provider data may help, but the publishing account can be false, compromised or automated.

Browsers, proxies and delivery networks may cache the object, so a device request may not reach the original platform. Compare endpoint and intermediary records when reconstructing the retrieval.

Key takeaway

Preserve the resolver content, account history and later destination as separate linked stages, without misidentifying the public platform as the control server.

Reference: CIM-152Cyber Incidents & Offender Methods