Skip to content

Domain Generation Algorithm (DGA)

Definition

Code embedded in malware that produces a large set of pseudo-random domain names on a scheduled basis. The malware tries each until one resolves, connecting it to command-and-control infrastructure even if most of the domain list has been blocked.

Embedded in
Malware
Function
Generates pseudo-random domain names
Purpose
Reach command-and-control infrastructure
Resilience
Survives partial domain blocklisting

Common questions

Why do defenders find DGA traffic useful as a detection signal?+

The generated domains are typically long, high-entropy strings unlike normal browsing traffic, and DNS resolution attempts for many such domains in a short window from one host is itself a strong indicator of compromise even before any domain resolves successfully.

Why can't defenders simply block all DGA domains in advance?+

The algorithm can produce thousands of candidate domains per day and the attacker registers only a small, often rotating subset, so blocklisting is a losing race. Defenders instead focus on detecting the query pattern or reverse-engineering the algorithm to predict future domains.

Related terms

A Record
A DNS resource record that maps a domain name to an IPv4 address. The primary attribution record in most investigations. An AAAA...
DNS Tunnelling
Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks...
Fast-Flux
An evasion technique in which a domain's A records cycle through a large pool of IP addresses with very short TTL values....
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
MISP (Malware Information Sharing Platform)
An open-source threat intelligence platform that enables structured sharing of IOCs and threat intelligence using STIX and other formats. Widely deployed by...
Passive DNS
A historical database of DNS resolutions collected by sensors at recursive resolvers or network taps. Passive DNS shows which IP addresses a...
Pyramid of Pain
A model proposed by David Bianco that ranks IOC types by the cost to an attacker of changing them when defenders start...
STIX (Structured Threat Information eXpression)
An OASIS open standard that defines a JSON-based language for describing cyber threat intelligence. STIX 2.1 defines objects for indicators, threat actors,...
TAXII (Trusted Automated eXchange of Intelligence Information)
The transport protocol companion to STIX. TAXII defines how STIX data is exchanged between servers and clients over HTTPS, enabling automated ingestion...
WHOIS
A query protocol that returns registration data for a domain, including registrant name, organisation, email, nameservers, and registration and expiry dates. Since...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.