logo

PowerShell DNS Command & Control with dnscat2-powershell

ID: aab5b0a5-c71c-5d7b-ae4d-7cc1f5b117b4

STIX ID: report--aab5b0a5-c71c-5d7b-ae4d-7cc1f5b117b4

Feed Name: Black Hills Infosec Blog

Date Published: 2017-01-11

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive summary:** This post describes dnscat2 and a PowerShell client implementation that enables DNS-based command-and-control (C2). It provides setup instructions, demonstrates PowerShell-specific features (interactive PS shell, in-memory script loading, file upload/download), explains encryption and authentication options, shows tunnel/port-forwarding usage, and discusses evasion techniques (timing delays, packet sizing, choice of DNS query types) to reduce detection likelihood.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.