Skip to content

DNS Tunnelling

Definition

Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks other protocols. Indicators include unusually long domain names, high-entropy subdomains, and query volumes far above what name resolution alone would generate.

Technique
Encoding data inside DNS queries and responses
Purpose
Data exfiltration or covert command-and-control
Common indicator
Unusually long, high-entropy subdomains
Second indicator
Query volume far above normal name resolution

Common questions

Why do attackers choose DNS instead of a normal network channel?+

DNS traffic is almost always permitted outbound through firewalls because name resolution is essential to normal operation, so it is rarely blocked or closely inspected by default. That makes it an attractive channel for exfiltrating data or maintaining command-and-control from a network that otherwise restricts outbound connections.

How do investigators distinguish DNS tunnelling from legitimate high-volume DNS traffic?+

Legitimate DNS traffic from content delivery networks or software update checks tends to query a limited, predictable set of domains with normal-looking labels. Tunnelling traffic typically shows random-looking subdomains, unusually large query and response sizes, and a narrow set of destination domains queried repeatedly, which log analysis and entropy scoring can flag.

What DNS record types are commonly abused for tunnelling?+

TXT and NULL records are common because they can carry more arbitrary data than an A record, but CNAME and MX records have also been used. Any record type that returns attacker-controlled text back to the client can be repurposed to carry a covert response payload.

Related terms

A Record
A DNS resource record that maps a domain name to an IPv4 address. The primary attribution record in most investigations. An AAAA...
Beaconing
Periodic outbound connections from a compromised host to a command-and-control server, typically at regular intervals. The regularity of the interval, measured in...
Covert Channel
Any communication path that was not intended by the system designer and that bypasses access-control or monitoring policies. Network covert channels are...
Domain Generation Algorithm (DGA)
Code embedded in malware that produces a large set of pseudo-random domain names on a scheduled basis. The malware tries each until...
Entropy Analysis
A statistical technique that measures the randomness of data in a field or stream. Protocol fields that should contain low-entropy predictable values...
Fast-Flux
An evasion technique in which a domain's A records cycle through a large pool of IP addresses with very short TTL values....
Network Flow (NetFlow/IPFIX)
A summary record of a network conversation, storing source IP, destination IP, source port, destination port, protocol, byte count, and timestamps, without...
Packet Capture (PCAP)
The interception and recording of network packets as they traverse an interface. The raw data is stored in PCAP format and analysed...
Passive DNS
A historical database of DNS resolutions collected by sensors at recursive resolvers or network taps. Passive DNS shows which IP addresses a...
Port Number
A 16-bit integer in the TCP or UDP header that identifies the application-layer service at each endpoint. Well-known ports are assigned by...
Protocol Anomaly Detection
A detection method that compares observed network traffic against the formal specification of each protocol (its RFC or standard) and flags fields...
Storage Channel
A covert channel that encodes information in the value of a protocol field, such as the IP Identification field or a DNS...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.