logo

Bypassing Cylance: Part 2 – Using DNSCat2

ID: 0c7d2af6-3ad1-52fe-a4fd-6cbad9dabca1

STIX ID: report--0c7d2af6-3ad1-52fe-a4fd-6cbad9dabca1

Feed Name: Black Hills Infosec Blog

Threat Score
50/100

Date Published: 2017-03-28

Date Updated: 2026-04-27

Author: BHIS

...
...

This report documents testing of DNSCat2 to establish DNS-based command-and-control against a Cylance-protected environment; encrypted connections were dropped while unencrypted sessions succeeded and were not detected by Cylance, demonstrating the need for layered defenses such as application whitelisting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.