Hunting For Dns Tunneling With Zeek

Detects DNS tunneling and covert-channel data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, abnormally long query lengths, and unusual DNS record types (TXT/NULL/CNAME). Use when hunting for DNS-based data exfiltration or C2 covert channels in network traffic, or when triaging suspicious DNS query volume/patterns surfaced by Zeek logs.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/hunting-for-dns-tunneling-with-zeek commit 3be3f28a8a

Frequently asked questions

npx skillmds@latest add gabrielmoreira/hunting-for-dns-tunneling-with-zeek