DNS隧道数据泄露检测

原名:analyzing-dns-logs-for-exfiltration

分析 DNS 查询日志,检测通过 DNS 隧道进行的数据外泄行为。

分类
数据分析
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
0
收藏
0
发布
2026-08-18
更新
2026-08-26
TRACE 评分
3.6 / 5

内容概览

Use this skill when: - SOC teams suspect data exfiltration through DNS tunneling to bypass firewall/proxy controls - Threat intelligence indicates adversaries using DNS-based C2 channels (e.g., Cobalt Strike DNS beacon) - UEBA detects anomalous DNS query volumes from specific hosts - Malware analysis reveals DNS-over-HTTPS (DoH) or DNS tunneling capabilities Do not use for standard DNS troubleshooting or availability monitoring — this skill focuses on security-relevant DNS abuse detection. - DNS query logging enabled (Windows DNS Server, Bind, Infoblox, or Cisco Umbrella) - DNS logs ingested into SIEM (Splunk with Stream:DNS, dns sourcetype, or Zeek DNS logs) - Passive DNS data for historical domain resolution analysis - Baseline of normal DNS behavior (query volume, domain distribution, TXT record frequency) - Python with math and collections libraries for entropy calculation DNS tunnel…

查看 SKILL 详情