{"id":"T1071.004","name":"DNS","url":"https://attack.mitre.org/techniques/T1071/004","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0400","stix_id":"x-mitre-detection-strategy--c2721658-fa76-4b6f-9f84-50618de81ae0","name":"Behavioral Detection of DNS Tunneling and Application Layer Abuse","url":"https://attack.mitre.org/detectionstrategies/DET0400","analytics":[{"id":"AN1121","stix_id":"x-mitre-analytic--407bb9c9-0c31-4172-8dd3-bdd0547f2d1e","name":"Analytic 1121","description":"Detects high-frequency or anomalous DNS queries initiated by non-browser, non-system processes (e.g., PowerShell, rundll32, python.exe) used to establish command and control via DNS tunneling.","url":"https://attack.mitre.org/detectionstrategies/DET0400#AN1121","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"NSM:Flow","channel":"dns.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"QueryLengthThreshold","description":"Subdomain length for detecting base32/base64-encoded payloads"},{"field":"ProcessImageFilter","description":"Flag non-standard executables making DNS queries"},{"field":"TimeWindow","description":"Rate of queries in short interval per process"}],"live":true,"detection_strategies":["DET0400"],"techniques":["T1071.004"]},{"id":"AN1122","stix_id":"x-mitre-analytic--cc8183e1-9de4-469a-9117-79bf2e986e31","name":"Analytic 1122","description":"Detects local daemons or scripts generating outbound DNS queries with long or frequent subdomains, indicative of DNS tunneling via tools like `iodine`, `dnscat2`, or `dig` from cronjobs or reverse shells.","url":"https://attack.mitre.org/detectionstrategies/DET0400#AN1122","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"NSM:Flow","channel":"dns.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"SubdomainEntropyScore","description":"Detects encoded payloads or randomness in DNS labels"},{"field":"DaemonAllowList","description":"Allowlisted system daemons expected to perform frequent lookups"}],"live":true,"detection_strategies":["DET0400"],"techniques":["T1071.004"]},{"id":"AN1123","stix_id":"x-mitre-analytic--42a8c7a7-2773-4892-b647-40d3542ae4d2","name":"Analytic 1123","description":"Detects scripting environments (AppleScript, osascript, curl) or non-native tools performing DNS queries with encoded subdomains, often used for data exfiltration or beaconing.","url":"https://attack.mitre.org/detectionstrategies/DET0400#AN1123","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream 'eventMessage contains \"dns_request\"'","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"EntropyThreshold","description":"Tunable threshold for randomness in subdomain labels"},{"field":"UncommonProcessContext","description":"Filters on user-launched or cron-based queries"}],"live":true,"detection_strategies":["DET0400"],"techniques":["T1071.004"]},{"id":"AN1124","stix_id":"x-mitre-analytic--fe648823-66c8-4cc3-8a8e-38616194464c","name":"Analytic 1124","description":"Detects clients issuing DNS queries with high volume, long subdomain lengths, encoded payload patterns, or to known malicious infrastructure; indicative of DNS-based C2 channels.","url":"https://attack.mitre.org/detectionstrategies/DET0400#AN1124","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"dns.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"DomainReputationFeed","description":"List of suspicious/malicious C2 domains"},{"field":"QueryRatePerClient","description":"Tunable burst rate per IP per second"}],"live":true,"detection_strategies":["DET0400"],"techniques":["T1071.004"]},{"id":"AN1125","stix_id":"x-mitre-analytic--11d8dd9d-e8f3-40cd-b9fe-cc82b6c2e790","name":"Analytic 1125","description":"Detects unusual outbound DNS traffic from ESXi hosts, often from shell scripts, custom daemons, or malicious VIBs interacting with external DNS infrastructure outside the management plane.","url":"https://attack.mitre.org/detectionstrategies/DET0400#AN1125","platforms":["ESXi"],"log_source_references":[{"name":"esxi:syslog","channel":"/var/log/syslog.log","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"esxi-syslog"},{"name":"NSM:FLow","channel":"dns.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"OutboundDNSVolume","description":"Threshold for data volume and frequency from ESXi IPs"},{"field":"KnownGoodVIBs","description":"Baseline known packages for allowlist comparison"}],"live":true,"detection_strategies":["DET0400"],"techniques":["T1071.004"]}],"live":true,"version":"1.0","techniques":["T1071.004"]}],"sigma_rules":[{"id":"0d18728b-f5bf-4381-9dcf-915539fff6c2","title":"Suspicious Cobalt Strike DNS Beaconing - DNS Client","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"critical","date":"2023-01-16","modified":null,"description":"Detects a program that invoked suspicious DNS queries known from Cobalt Strike beacons","references":["https://www.icebrg.io/blog/footprints-of-fin7-tracking-actor-patterns","https://www.sekoia.io/en/hunting-and-detecting-cobalt-strike/"],"logsource":{"product":"windows","service":"dns-client"},"tags":["attack.t1071.004","attack.command-and-control"],"path":"rules/windows/builtin/dns_client/win_dns_client_mal_cobaltstrike.yml","techniques":["T1071.004"],"cves":[]},{"id":"2975af79-28c4-4d2f-a951-9095f229df29","title":"Cobalt Strike DNS Beaconing","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2018-05-10","modified":"2022-10-09","description":"Detects suspicious DNS queries known from Cobalt Strike beacons","references":["https://www.icebrg.io/blog/footprints-of-fin7-tracking-actor-patterns","https://www.sekoia.io/en/hunting-and-detecting-cobalt-strike/"],"logsource":{"category":"dns"},"tags":["attack.command-and-control","attack.t1071.004"],"path":"rules/network/dns/net_dns_mal_cobaltstrike.yml","techniques":["T1071.004"],"cves":[]},{"id":"2fdaf50b-9fd5-449f-ba69-f17248119af6","title":"Network Connection Initiated via Finger.EXE","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-19","modified":null,"description":"Detects network connections via finger.exe, which can be abused by threat actors to retrieve remote commands for execution on Windows devices.\nIn one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server.\nSince the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion.\nInvestigating such network connections can also help identify potential malicious infrastructure used by threat actors\n","references":["https://www.bleepingcomputer.com/news/security/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1071.004","attack.execution","attack.t1059.003"],"path":"rules/windows/network_connection/net_connection_win_finger.yml","techniques":["T1071.004","T1059.003"],"cves":[]},{"id":"3ceb2083-a27f-449a-be33-14ec1b7cc973","title":"Silence.EDA Detection","author":"Alina Stepchenkova, Group-IB, oscd.community","status":"test","level":"critical","date":"2019-11-01","modified":"2023-04-03","description":"Detects Silence EmpireDNSAgent as described in the Group-IP report","references":["https://www.group-ib.com/resources/threat-research/silence_2.0.going_global.pdf"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.execution","attack.t1059.001","attack.command-and-control","attack.t1071.004","attack.t1572","attack.impact","attack.t1529","attack.g0091","attack.s0363"],"path":"rules/windows/powershell/powershell_script/posh_ps_apt_silence_eda.yml","techniques":["T1059.001","T1071.004","T1572","T1529"],"cves":[]},{"id":"4153a907-2451-4e4f-a578-c52bb6881432","title":"Suspicious DNS Query with B64 Encoded String","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2018-05-10","modified":"2022-10-09","description":"Detects suspicious DNS queries using base64 encoding","references":["https://github.com/krmaxwell/dns-exfiltration"],"logsource":{"category":"dns"},"tags":["attack.exfiltration","attack.t1048.003","attack.command-and-control","attack.t1071.004"],"path":"rules/network/dns/net_dns_susp_b64_queries.yml","techniques":["T1048.003","T1071.004"],"cves":[]},{"id":"53ba33fd-3a50-4468-a5ef-c583635cfa92","title":"OilRig APT Schedule Task Persistence - System","author":"Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community","status":"test","level":"critical","date":"2018-03-23","modified":"2023-03-08","description":"Detects OilRig schedule task persistence as reported by Nyotron in their March 2018 report","references":["https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf"],"logsource":{"product":"windows","service":"system"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.defense-impairment","attack.g0049","attack.t1053.005","attack.s0111","attack.t1543.003","attack.t1112","attack.command-and-control","attack.t1071.004","detection.emerging-threats"],"path":"rules-emerging-threats/2018/TA/OilRig/win_system_apt_oilrig_mar18.yml","techniques":["T1053.005","T1543.003","T1112","T1071.004"],"cves":[]},{"id":"6b0c762f-0e1b-435f-a829-5943b08fe36a","title":"DNS Query To Katz Stealer Domains - Network","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-05-22","modified":null,"description":"Detects DNS queries to domains associated with Katz Stealer malware.\nKatz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems.\nIn Enterprise environments, DNS queries to these domains may indicate potential malicious activity or compromise.\n","references":["Internal research"],"logsource":{"category":"dns"},"tags":["attack.command-and-control","attack.t1071.004","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Katz-Stealer/net_dns_katz_stealer_domain.yml","techniques":["T1071.004"],"cves":[]},{"id":"7bdf2a7c-3acc-4091-9581-0a77dad1c5b5","title":"OilRig APT Registry Persistence","author":"Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community","status":"test","level":"critical","date":"2018-03-23","modified":"2023-03-08","description":"Detects OilRig registry persistence as reported by Nyotron in their March 2018 report","references":["https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.defense-impairment","attack.g0049","attack.t1053.005","attack.s0111","attack.t1543.003","attack.t1112","attack.command-and-control","attack.t1071.004","detection.emerging-threats"],"path":"rules-emerging-threats/2018/TA/OilRig/registry_event_apt_oilrig_mar18.yml","techniques":["T1053.005","T1543.003","T1112","T1071.004"],"cves":[]},{"id":"8ae51330-899c-4641-8125-e39f2e07da72","title":"DNS TXT Answer with Possible Execution Strings","author":"Markus Neis","status":"test","level":"high","date":"2018-08-08","modified":"2021-11-27","description":"Detects strings used in command execution in DNS TXT Answer","references":["https://twitter.com/stvemillertime/status/1024707932447854592","https://github.com/samratashok/nishang/blob/414ee1104526d7057f9adaeee196d91ae447283e/Backdoors/DNS_TXT_Pwnage.ps1"],"logsource":{"category":"dns"},"tags":["attack.command-and-control","attack.t1071.004"],"path":"rules/network/dns/net_dns_susp_txt_exec_strings.yml","techniques":["T1071.004"],"cves":[]},{"id":"98a96a5a-64a0-4c42-92c5-489da3866cb0","title":"DNS Exfiltration and Tunneling Tools Execution","author":"Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2019-10-24","modified":"2021-11-27","description":"Well-known DNS Exfiltration tools execution","references":["https://github.com/iagox86/dnscat2","https://github.com/yarrick/iodine"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.t1048.001","attack.command-and-control","attack.t1071.004","attack.t1132.001"],"path":"rules/windows/process_creation/proc_creation_win_dns_exfiltration_tools_execution.yml","techniques":["T1048.001","T1071.004","T1132.001"],"cves":[]},{"id":"9c3d6e32-f4c8-4d73-8b8f-95c3b383a13c","title":"DNS Query To Katz Stealer Domains","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-05-22","modified":null,"description":"Detects DNS queries to domains associated with Katz Stealer malware.\nKatz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems.\nIn Enterprise environments, DNS queries to these domains may indicate potential malicious activity or compromise.\n","references":["Internal Research"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1071.004","detection.emerging-threats"],"path":"rules-emerging-threats/2025/Malware/Katz-Stealer/dns_query_win_katz_stealer_domain.yml","techniques":["T1071.004"],"cves":[]},{"id":"c0580559-a6bd-4ef6-b9b7-83703d98b561","title":"OilRig APT Schedule Task Persistence - Security","author":"Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community","status":"test","level":"critical","date":"2018-03-23","modified":"2023-03-08","description":"Detects OilRig schedule task persistence as reported by Nyotron in their March 2018 report","references":["https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.defense-impairment","attack.g0049","attack.t1053.005","attack.s0111","attack.t1543.003","attack.t1112","attack.command-and-control","attack.t1071.004","detection.emerging-threats"],"path":"rules-emerging-threats/2018/TA/OilRig/win_security_apt_oilrig_mar18.yml","techniques":["T1053.005","T1543.003","T1112","T1071.004"],"cves":[]},{"id":"c082c2b0-525b-4dbc-9a26-a57dc4692074","title":"DNS Query by Finger Utility","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-11-19","modified":null,"description":"Detects DNS queries made by the finger utility, which can be abused by threat actors to retrieve remote commands for execution on Windows devices.\nIn one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server.\nSince the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion.\nInvestigating such DNS queries can also help identify potential malicious infrastructure used by threat actors for command and control (C2) communication.\n","references":["https://www.bleepingcomputer.com/news/security/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1071.004","attack.execution","attack.t1059.003"],"path":"rules/windows/dns_query/dns_query_win_finger.yml","techniques":["T1071.004","T1059.003"],"cves":[]},{"id":"ce6e34ca-966d-41c9-8d93-5b06c8b97a06","title":"OilRig APT Activity","author":"Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community","status":"test","level":"critical","date":"2018-03-23","modified":"2023-03-08","description":"Detects OilRig activity as reported by Nyotron in their March 2018 report","references":["https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.defense-impairment","attack.g0049","attack.t1053.005","attack.s0111","attack.t1543.003","attack.t1112","attack.command-and-control","attack.t1071.004","detection.emerging-threats"],"path":"rules-emerging-threats/2018/TA/OilRig/proc_creation_win_apt_oilrig_mar18.yml","techniques":["T1053.005","T1543.003","T1112","T1071.004"],"cves":[]},{"id":"cf5ee356-65c4-4556-8d11-6977fcdfed4b","title":"Low Reputation Effective Top-Level Domain (eTLD)","author":"Norbert Jaśniewicz (AlphaSOC)","status":"experimental","level":"medium","date":"2025-08-04","modified":null,"description":"Detects DNS queries to domains within known low reputation eTLDs. This rule uses AlphaSOC's threat intelligence data and is updated on a monthly basis.","references":["https://feeds.alphasoc.net/bad-etlds.txt"],"logsource":{"category":"dns"},"tags":["attack.command-and-control","attack.t1071.004","attack.initial-access","detection.threat-hunting"],"path":"rules-threat-hunting/network/net_dns_low_reputation_etld.yml","techniques":["T1071.004"],"cves":[]},{"id":"f356a9c4-effd-4608-bbf8-408afd5cd006","title":"Suspicious Cobalt Strike DNS Beaconing - Sysmon","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-11-09","modified":"2023-01-16","description":"Detects a program that invoked suspicious DNS queries known from Cobalt Strike beacons","references":["https://www.icebrg.io/blog/footprints-of-fin7-tracking-actor-patterns","https://www.sekoia.io/en/hunting-and-detecting-cobalt-strike/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1071.004"],"path":"rules/windows/dns_query/dns_query_win_mal_cobaltstrike.yml","techniques":["T1071.004"],"cves":[]},{"id":"f8c1e80b-c73a-476a-ae24-6c72528b1521","title":"DNS Query To Common Malware Hosting and Shortener Services","author":"Ahmed Nosir (@egycondor)","status":"experimental","level":"medium","date":"2025-06-02","modified":null,"description":"Detects DNS queries to domains commonly used by threat actors to host malware payloads or redirect through URL shorteners.\nThese include platforms like Cloudflare Workers, TryCloudflare, InfinityFree, and URL shorteners such as tinyurl and lihi.cc.\nSuch DNS activity can indicate potential delivery or command-and-control communication attempts.\n","references":["https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1071.004"],"path":"rules/windows/dns_query/dns_query_win_common_malware_hosting_services.yml","techniques":["T1071.004"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}