kevmap

TechniquesT1071 › T1071.004

T1071.004 DNS

command and control — ESXi, Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
5
analytics
17
Sigma rules tagged attack.t1071.004
0
KEV CVEs mapped here
<p>Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.</p><p>The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.</p><p>DNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e. Protocol Tunneling). The commands may be embedded into different DNS records, for example, TXT or A records. DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices. Infrequent communication conceals the malicious DNS traffic with normal DNS traffic.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1071.004

Author: Nasreddine Bencherchali (Nextron Systems) · 2023-01-16 · logsource: product=windows service=dns-client · 0d18728b-f5bf-4381-9dcf-915539fff6c2
Detects a program that invoked suspicious DNS queries known from Cobalt Strike beacons
Techniques: T1071.004
Author: Florian Roth (Nextron Systems) · 2018-05-10 (modified 2022-10-09) · logsource: category=dns · 2975af79-28c4-4d2f-a951-9095f229df29
Detects suspicious DNS queries known from Cobalt Strike beacons
Techniques: T1071.004
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-19 · logsource: product=windows category=network_connection · 2fdaf50b-9fd5-449f-ba69-f17248119af6
Detects network connections via finger.exe, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such network connections can also help identify potential malicious infrastructure used by threat actors
Techniques: T1071.004T1059.003
Author: Alina Stepchenkova, Group-IB, oscd.community · 2019-11-01 (modified 2023-04-03) · logsource: product=windows category=ps_script · 3ceb2083-a27f-449a-be33-14ec1b7cc973
Detects Silence EmpireDNSAgent as described in the Group-IP report
Author: Florian Roth (Nextron Systems) · 2018-05-10 (modified 2022-10-09) · logsource: category=dns · 4153a907-2451-4e4f-a578-c52bb6881432
Detects suspicious DNS queries using base64 encoding
Techniques: T1048.003T1071.004
Author: Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community · 2018-03-23 (modified 2023-03-08) · logsource: product=windows service=system · 53ba33fd-3a50-4468-a5ef-c583635cfa92
Detects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-05-22 · logsource: category=dns · 6b0c762f-0e1b-435f-a829-5943b08fe36a
Detects DNS queries to domains associated with Katz Stealer malware. Katz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems. In Enterprise environments, DNS queries to these domains may indicate potential malicious activity or compromise.
Techniques: T1071.004
Author: Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community · 2018-03-23 (modified 2023-03-08) · logsource: product=windows category=registry_event · 7bdf2a7c-3acc-4091-9581-0a77dad1c5b5
Detects OilRig registry persistence as reported by Nyotron in their March 2018 report
Author: Markus Neis · 2018-08-08 (modified 2021-11-27) · logsource: category=dns · 8ae51330-899c-4641-8125-e39f2e07da72
Detects strings used in command execution in DNS TXT Answer
Techniques: T1071.004
Author: Daniil Yugoslavskiy, oscd.community · 2019-10-24 (modified 2021-11-27) · logsource: product=windows category=process_creation · 98a96a5a-64a0-4c42-92c5-489da3866cb0
Well-known DNS Exfiltration tools execution
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-05-22 · logsource: product=windows category=dns_query · 9c3d6e32-f4c8-4d73-8b8f-95c3b383a13c
Detects DNS queries to domains associated with Katz Stealer malware. Katz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems. In Enterprise environments, DNS queries to these domains may indicate potential malicious activity or compromise.
Techniques: T1071.004
Author: Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community · 2018-03-23 (modified 2023-03-08) · logsource: product=windows service=security · c0580559-a6bd-4ef6-b9b7-83703d98b561
Detects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
Author: Swachchhanda Shrawan Poudel (Nextron Systems) · 2025-11-19 · logsource: product=windows category=dns_query · c082c2b0-525b-4dbc-9a26-a57dc4692074
Detects DNS queries made by the finger utility, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such DNS queries can also help identify potential malicious infrastructure used by threat actors for command and control (C2) communication.
Techniques: T1071.004T1059.003
OilRig APT Activity criticaltest
Author: Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community · 2018-03-23 (modified 2023-03-08) · logsource: product=windows category=process_creation · ce6e34ca-966d-41c9-8d93-5b06c8b97a06
Detects OilRig activity as reported by Nyotron in their March 2018 report
Author: Norbert Jaśniewicz (AlphaSOC) · 2025-08-04 · logsource: category=dns · cf5ee356-65c4-4556-8d11-6977fcdfed4b
Detects DNS queries to domains within known low reputation eTLDs. This rule uses AlphaSOC's threat intelligence data and is updated on a monthly basis.
Techniques: T1071.004
Author: Florian Roth (Nextron Systems) · 2021-11-09 (modified 2023-01-16) · logsource: product=windows category=dns_query · f356a9c4-effd-4608-bbf8-408afd5cd006
Detects a program that invoked suspicious DNS queries known from Cobalt Strike beacons
Techniques: T1071.004
Author: Ahmed Nosir (@egycondor) · 2025-06-02 · logsource: product=windows category=dns_query · f8c1e80b-c73a-476a-ae24-6c72528b1521
Detects DNS queries to domains commonly used by threat actors to host malware payloads or redirect through URL shorteners. These include platforms like Cloudflare Workers, TryCloudflare, InfinityFree, and URL shorteners such as tinyurl and lihi.cc. Such DNS activity can indicate potential delivery or command-and-control communication attempts.
Techniques: T1071.004

Rules tagged at the parent level (attack.t1071) 7

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Aleksey Potapov, oscd.community · 2019-10-22 (modified 2023-02-13) · logsource: product=windows category=process_creation · 03552375-cc2c-4883-bbe4-7958d5a980be
Detects SILENTTRINITY stager use via PE metadata
Techniques: T1071
Author: @kostastsale · 2024-08-16 · logsource: product=windows category=process_creation · 0ea52357-cd59-4340-9981-c46c7e900428
Detects the execution of rundll32.exe with the oledb32.dll library to open a UDL file. Threat actors can abuse this technique as a phishing vector to capture authentication credentials or other sensitive data.
Techniques: T1218.011T1071
Author: Tim Burrell · 2020-02-07 (modified 2023-01-02) · logsource: product=windows service=dns-server-analytic · 3db10f25-2527-4b79-8d4b-471eb900ee29
Detects artefacts associated with activity group GALLIUM - Microsoft Threat Intelligence Center indicators released in December 2019.
Techniques: T1071
GALLIUM IOCs hightest
Author: Tim Burrell · 2020-02-07 (modified 2024-11-23) · logsource: product=windows category=process_creation · 440a56bf-7873-4439-940a-1c8a671073c2
Detects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.
Techniques: T1212T1071
Author: Daniel Koifman (KoifSec) · 2025-11-29 · logsource: product=windows category=process_creation · 5bac7a56-da88-4c27-922e-c81e113b20cb
Detects GitHub self-hosted runners executing workflows on local infrastructure that could be abused for persistence and code execution. Shai-Hulud is an npm supply chain worm targeting CI/CD environments. It installs runners on compromised systems to maintain access after credential theft, leveraging their access to secrets and internal networks.
Techniques: T1102.002T1071
Author: Aleksey Potapov, oscd.community · 2019-10-22 (modified 2023-02-17) · logsource: product=windows category=image_load · 75c505b1-711d-4f68-a357-8c3fe37dbf2d
Detects SILENTTRINITY stager dll loading activity
Techniques: T1071
Author: Sohan G (D4rkCiph3r) · 2023-02-18 · logsource: product=macos category=process_creation · e0cfaecd-602d-41af-988d-f6ccebb2af26
Detects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters