Detecting Exfiltration Over Dns With Zeek

Detect DNS-based data exfiltration by analyzing Zeek dns.log for high-entropy subdomains, oversized TXT/NULL records, and anomalous query volume or patterns. Use when investigating suspected DNS tunneling, covert C2 over DNS, or data exfiltration hidden in DNS queries against network traffic captured by Zeek.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/detecting-exfiltration-over-dns-with-zeek commit ea8255391e

Frequently asked questions

npx skillmds@latest add gabrielmoreira/detecting-exfiltration-over-dns-with-zeek