BigHugger
sk Skill · mukul975

detecting-dns-exfiltration-with-dns-query-analysis

Detect data exfiltration via DNS tunneling (tools like iodine, dnscat2, dns2tcp) by analyzing query entropy, subdomain length, query volume to single domains, TXT/CNAME/NULL record abuse, and oversized response payloads using passive DNS monitoring and statistical/ML methods. Use when hunting for covert DNS-based data exfiltration or building a passive DNS anomaly detection capability.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
yamldns-exfiltrationdns-tunnelingnetwork-monitoringdata-exfiltrationthreat-detectionpassive-dnsentropy-analysisPythoniodinednscat2bashpythonspl
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python