Medium severity Attack Technique

DNS Tunneling

Data is smuggled through DNS queries and responses, bypassing egress filters.

Overview

Because resolvers must be reachable from every host, DNS rarely gets inspected. Encoding payloads into subdomain labels turns ordinary lookups into a bidirectional covert channel.\nIt is used for command-and-control callbacks and for exfiltrating data one label at a time.\nWatching for high-entropy subdomains and unexpected TXT volume is the main detection route.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Very long or high-entropy subdomain queries
  • Unusual TXT record volume
  • Long DNS session durations to one authoritative server

Controls that stop it

  • Segment the Network and Restrict Egress

    Do not let every host talk to every other host or to the whole internet. Segment by role, deny inbound administration from user networks, and filter outbound traffic so only the destinations a workload genuinely needs are reachable. Egress control is what stops an SSRF or an implant from reaching cloud metadata and command infrastructure.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used