Detecting Command And Control Over Dns

Detect command-and-control (C2) traffic tunneled over DNS from tools like Iodine, dnscat2, dns2tcp, and Cobalt Strike DNS beacon, using Shannon entropy analysis of query subdomains, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signatures. Use when investigating suspected DNS tunneling, classifying DGA domains, detecting DNS beaconing, or building DNS anomaly rules for a SOC/SIEM.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/detecting-command-and-control-over-dns commit 080a64ab33

Frequently asked questions

npx skillmds@latest add gabrielmoreira/detecting-command-and-control-over-dns