Detecting Dns Exfiltration With Dns Query Analysis

Detect data exfiltration via DNS tunneling (tools like iodine, dnscat2, dns2tcp) by analyzing query entropy, subdomain length, query volume to single domains, TXT/CNAME/NULL record abuse, and oversized response payloads using passive DNS monitoring and statistical/ML methods. Use when hunting for covert DNS-based data exfiltration or building a passive DNS anomaly detection capability.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/detecting-dns-exfiltration-with-dns-query-analysis commit 16c442f147

Frequently asked questions

npx skillmds@latest add gabrielmoreira/detecting-dns-exfiltration-with-dns-query-analysis