Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0400 — Behavioral Detection of DNS Tunneling and Application Layer Abuse
DET0400

Behavioral Detection of DNS Tunneling and Application Layer Abuse

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN1121 Analytic 1121
Windows

Detects high-frequency or anomalous DNS queries initiated by non-browser, non-system processes (e.g., PowerShell, rundll32, python.exe) used to establish command and control via DNS tunneling.

WinEventLog:Sysmon EventCode=3, 22 NSM:Flow dns.log
[QueryLengthThreshold] Subdomain length for detecting base32/base64-encoded payloads
[ProcessImageFilter] Flag non-standard executables making DNS queries
[TimeWindow] Rate of queries in short interval per process
AN1122 Analytic 1122
Linux

Detects local daemons or scripts generating outbound DNS queries with long or frequent subdomains, indicative of DNS tunneling via tools like `iodine`, `dnscat2`, or `dig` from cronjobs or reverse shells.

auditd:SYSCALL execve NSM:Flow dns.log
[SubdomainEntropyScore] Detects encoded payloads or randomness in DNS labels
[DaemonAllowList] Allowlisted system daemons expected to perform frequent lookups
AN1123 Analytic 1123
macOS

Detects scripting environments (AppleScript, osascript, curl) or non-native tools performing DNS queries with encoded subdomains, often used for data exfiltration or beaconing.

macos:unifiedlog log stream 'eventMessage contains "dns_request"'
[EntropyThreshold] Tunable threshold for randomness in subdomain labels
[UncommonProcessContext] Filters on user-launched or cron-based queries
AN1124 Analytic 1124
Network Devices

Detects clients issuing DNS queries with high volume, long subdomain lengths, encoded payload patterns, or to known malicious infrastructure; indicative of DNS-based C2 channels.

NSM:Flow dns.log
[DomainReputationFeed] List of suspicious/malicious C2 domains
[QueryRatePerClient] Tunable burst rate per IP per second
AN1125 Analytic 1125
ESXi

Detects unusual outbound DNS traffic from ESXi hosts, often from shell scripts, custom daemons, or malicious VIBs interacting with external DNS infrastructure outside the management plane.

esxi:syslog /var/log/syslog.log NSM:FLow dns.log
[OutboundDNSVolume] Threshold for data volume and frequency from ESXi IPs
[KnownGoodVIBs] Baseline known packages for allowlist comparison

Detected Techniques

1

Command & Control (1)

Details

MITRE ID
DET0400
STIX ID
x-mitre-detection-strategy--c2721658-fa76-4b6f-9f84-50618de81ae0
Analytics
5
Techniques Detected
1
By Tactic
Command & Control
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.