BigHugger
sk Skill · mukul975

detecting-command-and-control-over-dns

Detect command-and-control (C2) traffic tunneled over DNS from tools like Iodine, dnscat2, dns2tcp, and Cobalt Strike DNS beacon, using Shannon entropy analysis of query subdomains, ML-based DGA classification, passive DNS correlation, and Zeek/Suricata signatures. Use when investigating suspected DNS tunneling, classifying DGA domains, detecting DNS beaconing, or building DNS anomaly rules for a SOC/SIEM.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
pythonbashthreat-detectionPythonnetwork-forensicsdgatunnelingc2dns
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0.0
Licence
Apache-2.0
Host stars
33k
Host language
Python