Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution.
.claude/skills/cyberstrikeus-t1568-001-fast-flux-dns/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-12 | ✗→✓ | ▲ Improved | -71% | 0% |
| case-04 | ✗→✓ | ▲ Improved | -26% | 0% |
| case-09 | ✗→✓ | ▲ Improved | -46% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 60% | 0% |
| case-15 | ✗→✓ | ▲ Improved | -40% | 0% |
> Sub-technique of: T1568
Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution. This technique uses a fully qualified domain name, with multiple IP addresses assigned to it which are swapped with high frequency, using a combination of round robin IP addressing and short Time-To-Live (TTL) for a DNS resource record.
The simplest, "single-flux" method, involves registering and de-registering an addresses as part of the DNS A (address) record list for a single DNS name. These registrations have a five-minute average lifespan, resulting in a constant shuffle of IP address resolution.
In contrast, the "double-flux" method registers and de-registers an address as part of the DNS Name Server record list for the DNS zone, providing additional resilience for the connection. With double-flux additional hosts can act as a proxy to the C2 host, further insulating the true source of the C2 channel.
Platforms: Linux, macOS, Windows, ESXi
> Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.
No specific mitigations documented for this technique.
| Finding | Severity | Impact | | ---------------------------------- | -------- | ------------------- | | Fast Flux DNS technique applicable | Medium | Command And Control |
| CWE ID | Title | | ------- | ---------------------------------- | | CWE-300 | Channel Accessible by Non-Endpoint |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 39,689 | 30,182 | -24% | 1 | 1 | 0% | 4,662 | 4,851 | +4% | 0 | 0 | — |
case-12 | fail→pass | 34,232 | 8,196 | -76% | 1 | 1 | 0% | 4,010 | 1,171 | -71% | 0 | 0 | — |
case-02 | fail→fail | 24,015 | 31,609 | +32% | 1 | 1 | 0% | 3,832 | 5,304 | +38% | 0 | 0 | — |
case-03 | fail→fail | 54,700 | 18,628 | -66% | 1 | 1 | 0% | 7,106 | 4,123 | -42% | 0 | 0 | — |
case-04 | fail→pass | 16,313 | 4,161 | -74% | 1 | 1 | 0% | 1,919 | 1,428 | -26% | 0 | 0 | — |
case-05 | pass→pass | 21,698 | 25,521 | +18% | 1 | 1 | 0% | 2,804 | 4,279 | +53% | 0 | 0 | — |
case-06 | pass→pass | 16,183 | 2,134 | -87% | 1 | 1 | 0% | 2,499 | 1,158 | -54% | 0 | 0 | — |
case-07 | pass→pass | 9,668 | 8,480 | -12% | 1 | 1 | 0% | 838 | 1,258 | +50% | 0 | 0 | — |
case-08 | pass→pass | 9,649 | 10,037 | +4% | 1 | 1 | 0% | 1,671 | 1,371 | -18% | 0 | 0 | — |
case-09 | fail→pass | 16,729 | 6,488 | -61% | 1 | 1 | 0% | 2,007 | 1,091 | -46% | 0 | 0 | — |
case-10 | fail→pass | 9,820 | 9,516 | -3% | 1 | 1 | 0% | 1,529 | 2,451 | +60% | 0 | 0 | — |
case-11 | fail→fail | 20,914 | 39,191 | +87% | 1 | 1 | 0% | 2,681 | 4,043 | +51% | 0 | 0 | — |
case-13 | pass→pass | 20,763 | 20,141 | -3% | 1 | 1 | 0% | 2,282 | 2,925 | +28% | 0 | 0 | — |
case-14 | pass→pass | 17,552 | 2,018 | -89% | 1 | 1 | 0% | 2,027 | 1,121 | -45% | 0 | 0 | — |
case-15 | fail→pass | 9,911 | 6,392 | -36% | 1 | 1 | 0% | 1,726 | 1,037 | -40% | 0 | 0 | — |
case-16 | pass→pass | 38,897 | 8,019 | -79% | 1 | 1 | 0% | 1,629 | 1,279 | -21% | 0 | 0 | — |
case-17 | pass→pass | 14,600 | 12,797 | -12% | 1 | 1 | 0% | 1,535 | 1,934 | +26% | 0 | 0 | — |
case-18 | fail→pass | 14,392 | 8,178 | -43% | 1 | 1 | 0% | 2,369 | 1,473 | -38% | 0 | 0 | — |
case-19 | pass→pass | 7,553 | 6,770 | -10% | 1 | 1 | 0% | 459 | 1,137 | +148% | 0 | 0 | — |
case-20 | fail→pass | 15,848 | 10,159 | -36% | 1 | 1 | 0% | 1,729 | 1,641 | -5% | 0 | 0 | — |
case-21 | pass→pass | 30,895 | 28,014 | -9% | 1 | 1 | 0% | 4,130 | 4,255 | +3% | 0 | 0 | — |
case-22 | pass→pass | 23,297 | 27,607 | +19% | 1 | 1 | 0% | 3,084 | 4,489 | +46% | 0 | 0 | — |
case-23 | pass→pass | 31,187 | 37,739 | +21% | 1 | 1 | 0% | 4,211 | 6,728 | +60% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +30 percentage points is the difference between those two pass rates over the 23 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.