Free kit

Free AI Tabletop Exercise Kit for SMBs

Sign up for the Cyber Defense & AI Brief and get it free.

Get the free kit

UC-L3-012

DNS Tunneling Detection

DNS query logs

Use case development / Prevent Data Exfiltration / Detect DNS Exfiltration

sigma

Detection rule

title: High Entropy DNS Queries
status: experimental
description: Detects DNS queries with unusually long or random-looking subdomains
logsource:
  product: dns
detection:
  selection:
    query_length: '>50'
  condition: selection | count() by src_ip > 100
  timeframe: 1h
falsepositives:
  - CDN traffic
  - Some legitimate services
level: medium
tags:
  - attack.exfiltration
  - attack.t1048

Test cases

  • Generate DNS queries with encoded data

False positive guidance

Whitelist known CDN and legitimate long domain services.

Detection course