Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Command and Control/ T1071.004

T1071.004DNS

T1071.004 — DNS is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 33 detection use cases covering it and 166 threat-intel articles citing it.

Command and Control
View on the matrix → Filter Detection Library MITRE official spec ↗
33Use cases
166Articles
0Sub-techniques
1Tactic

Use cases covering this technique (33)

Beaconing — periodic outbound to small set of destinations Internal c2 · alerting DSP DNS tunneling / TXT-heavy domain queries Internal c2 · hunting DSP Windows AI Platform DNS Query ESCU actions · hunting P Windows Credential Target Information Structure in Commandline ESCU actions · alerting P Windows Kerberos Coercion via DNS ESCU actions · alerting P Windows Short Lived DNS Record ESCU actions · alerting P Windows Visual Basic Commandline Compiler DNSQuery ESCU actions · alerting P DNS Kerberos Coercion ESCU actions · alerting P Excessive DNS Failures ESCU actions · hunting P Windows DNS Query Request by Telegram Bot API ESCU actions · hunting P DNS Query Length Outliers - MLTK ESCU actions · hunting P DNS Query Requests Resolved by Unauthorized DNS Servers ESCU actions · alerting P DNS record changed ESCU actions · alerting P [LLM] OWAReaper C2 / exfiltration egress to TA488 CDN and DNS-tunnel domains Bespoke c2 · alerting DSΣPDDCS [LLM] BINDCLOAK C2 beacon to cert.hypersnet.com / ssl.blsouqs.com Bespoke c2 · alerting DSΣPDDCS [LLM] CAV3RN/HOLLOWGRAPH DNS AAAA config-recovery beaconing to cloudlanecdn[.]com Bespoke c2 · alerting DSΣPCS [LLM] TuxBot fallback C2 via digikalas.online DGA subdomains and DNS TXT queries Bespoke c2 · hunting DSΣPCS [LLM] Apache Camel DNS SSRF: inbound HTTP request carrying dns.server / dns.name control headers Bespoke delivery · hunting SΣP [LLM] Apache Camel DNS SSRF egress: app server (java) resolving via external / attacker DNS resolver Bespoke actions · hunting DSΣPDDCS [LLM] DNS resolution of TeamPCP typosquat exfil domain scan.aquasecurtiy.org Bespoke c2 · alerting DSΣPCS [LLM] OceanLotus SPECTRALVIPER C2 communication to FireAnt-campaign domains/IPs Bespoke c2 · hunting DSΣPDDCS [LLM] Nx Console / Shai-Hulud C2 connection (t.m-kosche.com, check.git-service.com, filev2.getsession.org, api.masscan.cloud, 83.142.209.194) Bespoke c2 · alerting DSΣPDDCS [LLM] DNS / Network egress to TeamPCP Nx Console C2 domain check.git-service.com Bespoke c2 · alerting DSΣPDDCS [LLM] DNS lookup for azurestaticprovider[.]net node-ipc exfil domain Bespoke c2 · alerting DSΣPDDCS [LLM] Session/Oxen P2P exfil DNS or TCP to getsession.org from build/CI host Bespoke c2 · alerting DSΣPDD [LLM] IoliteLabs IOC sweep: rraghh.com / oortt.com hostnames + campaign file hashes Bespoke c2 · hunting DSΣPDD [LLM] bittensor-wallet 4.0.2 backdoor C2 domain contact (opentensor-* lookalikes) Bespoke c2 · alerting DSΣPDD [LLM] DNS tunneling exfiltration pattern to *.t.opentensor-cdn.com (hex chunk/index/total/session) Bespoke c2 · alerting DSΣPDD [LLM] DNS/HTTP egress to CanisterWorm ICP canister C2 (tdtqy-oyaaa-aaaae-af2dq-cai) Bespoke c2 · alerting DSΣPDDCS [LLM] GhostChat C2/staging infrastructure contact (hitpak.org, buildthenations.info, fkclb.com) Bespoke c2 · alerting DSΣPDDCS [LLM] Java process fetching first-seen external URL/DNS — Commons Config url/dns lookup (CVE-2022-33980) Bespoke c2 · hunting DSPDDCS [LLM] npm dropper exfiltration to pkgio.com telemetry server Bespoke exfil · alerting DSΣPDDCS [LLM] npm dropper DNS exfil to pkgio.com / game-note.com (gxm-reference campaign) Bespoke c2 · alerting DSΣPCS

Articles citing this technique (166)