Learn how to effectively investigate, contain and remediate this incident by following our Response Playbook.
Traditional threat intelligence relies heavily on known Indicators of Compromise (IoCs) to block malicious activity. However, cyber adversaries actively bypass these defenses using Domain Generation Algorithms (DGAs) embedded within malware families. These algorithms dynamically generate a large number of pseudo-random domain names on the fly. Because these domains are entirely new and constantly changing, they will never appear on standard threat intelligence blocklists, creating a massive blind spot for conventional security stacks.
These generated domains serve a specific, dangerous purpose: they act as highly resilient backup Command and Control (C2) channels. By querying thousands of random domains, infected hosts can successfully maintain communication with adversarial infrastructure even if their primary C2 domains are blocked or taken down.
Lumu fills this critical gap in traditional threat intelligence by shifting the focus from static lists to behavioral analysis. Lumu continuously monitors network metadata for the anomalous pattern of endpoints querying massive volumes of randomized domains. Once this anomaly reaches a high confidence threshold, it is automatically elevated into a confirmed DGA Incident.
By detecting this algorithm-driven activity, Lumu provides immense value by delivering visibility into three critical areas:
This document outlines how the Lumu Portal delivers valuable insight into the detection of this attack by providing the necessary context to support the decision-making of your organization's response team.
To facilitate forensic analysis and scope determination, the Lumu Portal captures specific metadata fields regarding the algorithm-driven behavior. The data collected for this incident includes:
The Lumu Portal delivers the collected data to facilitate rapid triage and decision-making. The data is displayed as follows:
1. Summary
This section highlights critical timeline and operational metrics. It displays the First Contact and Last Contact timestamps, alongside the Time to Respond and Incident Duration. This data establishes a general scope of the incident, allowing analysts to identify exactly when the automated queries began and how long the endpoint has been compromised.
2. Dynamic Resolution Activity
This section aggregates the most relevant data regarding the anomalous queries. It quantifies the severity of the compromise by displaying the highly randomized domains alongside the volume of connection attempts originating from the host.
While the Lumu Portal displays the most critical data points—such as the top attacking sources and target users—complex attacks often involve volumes of traffic that exceed what can be efficiently displayed on a single screen. For that reason, the Lumu allows in-depth investigations with its Export Feature. It allows analysts to move beyond the high-level summary and access the complete forensic dataset of the incident.
You can export data using the download button located at the top of the page (1) or using the button below the Summary section (2).
You can export the complete dataset of the incident lifecycle using the following options: