Skip to content

Hide Navigation Hide TOC

DNS tunneling (b1b60f03-a603-506f-870b-7ea4da0cbeaa)

DNS tunneling - tunneling another protocol over DNS - The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal expected traffic.

Cluster A Galaxy A Cluster B Galaxy B Level
DNS tunneling (b1b60f03-a603-506f-870b-7ea4da0cbeaa) FIRST DNS Abuse Techniques Matrix DNS - T1071.004 (1996eef1-ced3-4d7f-bf94-33298cabbf72) Attack Pattern 1
Application Layer Protocol - T1071 (355be19c-ffc9-46d5-8d50-d6a036c675b6) Attack Pattern DNS - T1071.004 (1996eef1-ced3-4d7f-bf94-33298cabbf72) Attack Pattern 2