Detecting Command And Control Over Dns

'Detects command-and-control (C2) communications tunneled through DNS protocol including DNS tunneling tools (Iodine, dnscat2, dns2tcp, Cobalt Strike DNS beacon), domain generation algorithms (DGA), encoded payload delivery via TXT/CNAME records, and DNS beaconing patterns. Covers Shannon entropy analysis of query subdomains, statistical anomaly detection, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signature development. Activates for requests involving DNS-based C2 detection, DNS tunnel identification, suspicious DNS traffic investigation, or DGA domain classification. '

thedixitjain ce8f2e3 4 files · 101.6 KB Updated 2 repo stars

File contents

thedixitjain/the-mega-skill-library/tree/main/library/data-science-and-ml/detecting-command-and-control-over-dns commit ce8f2e339f

Frequently asked questions

npx skillmds add thedixitjain/detecting-command-and-control-over-dns