DNS隧道数据泄露检测
原名:analyzing-dns-logs-for-exfiltration
分析 DNS 查询日志,检测通过 DNS 隧道进行的数据外泄行为。
- 分类
- 数据分析
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-26
- TRACE 评分
- 3.6 / 5
内容概览
Use this skill when: - SOC teams suspect data exfiltration through DNS tunneling to bypass firewall/proxy controls - Threat intelligence indicates adversaries using DNS-based C2 channels (e.g., Cobalt Strike DNS beacon) - UEBA detects anomalous DNS query volumes from specific hosts - Malware analysis reveals DNS-over-HTTPS (DoH) or DNS tunneling capabilities Do not use for standard DNS troubleshooting or availability monitoring — this skill focuses on security-relevant DNS abuse detection. - DNS query logging enabled (Windows DNS Server, Bind, Infoblox, or Cisco Umbrella) - DNS logs ingested into SIEM (Splunk with Stream:DNS, dns sourcetype, or Zeek DNS logs) - Passive DNS data for historical domain resolution analysis - Baseline of normal DNS behavior (query volume, domain distribution, TXT record frequency) - Python with math and collections libraries for entropy calculation DNS tunnel…