Applied Cybernetics Group
T1071.004 — DNS
- Technique
T1071.004- Tactics
- Command and Control
- MISP citations
- 0
- KEV CVEs mapped
- 0
- Community rules
- 17
- thrunt rules
- 1
- Upstream
- https://attack.mitre.org/techniques/T1071/004
MITRE description
Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.(Citation: PAN DNS Tunneling)(Citation: Medium DnsTunneling) DNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e. [Protocol Tunneling](https://attack.mitre.org/techniques/T1572)). The commands may be embedded into different DNS records, for example, TXT or A records.(Citation: OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government) DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices.(Citation: DNS Beacons) Infrequent communication conceals the malicious DNS traffic with normal DNS traffic.
Detection coverage
thrunt rules
SigmaHQ community rules
- OilRig APT Activity (emerging-threats)
- OilRig APT Registry Persistence (emerging-threats)
- OilRig APT Schedule Task Persistence - Security (emerging-threats)
- OilRig APT Schedule Task Persistence - System (emerging-threats)
- DNS Query To Katz Stealer Domains (emerging-threats)
- DNS Query To Katz Stealer Domains - Network (emerging-threats)
- Low Reputation Effective Top-Level Domain (eTLD) (threat-hunting)
- Cobalt Strike DNS Beaconing (core)
- Suspicious DNS Query with B64 Encoded String (core)
- DNS TXT Answer with Possible Execution Strings (core)
- Suspicious Cobalt Strike DNS Beaconing - DNS Client (core)
- DNS Query To Common Malware Hosting and Shortener Services (core)
- DNS Query by Finger Utility (core)
- Suspicious Cobalt Strike DNS Beaconing - Sysmon (core)
- Network Connection Initiated via Finger.EXE (core)
- Silence.EDA Detection (core)
- DNS Exfiltration and Tunneling Tools Execution (core)