logo

DNS Over HTTPS for Cobalt Strike

ID: b85ba90d-f290-5bfe-93b6-111fec68139f

STIX ID: report--b85ba90d-f290-5bfe-93b6-111fec68139f

Feed Name: Black Hills Infosec Blog

Date Published: 2021-11-17

Date Updated: 2026-04-27

Author: BHIS

...
...

This post explains how to run Cobalt Strike Beacon over DNS over HTTPS (DoH) using the TitanLdr user-defined reflective loader to hook DNSQuery_A and route queries through reputable DoH providers (e.g., Google, Quad9, Cloudflare, OpenDNS, HE), including a fork that randomizes among multiple resolvers, build instructions, and Cobalt Strike setup. It highlights advantages (valid SSL, no third-party infrastructure, trusted domains), tradeoffs (lower throughput due to TXT record limits, reliance on public DoH endpoints), and detection/mitigation ideas such as combining DNS monitoring with SSL inspection and blocking outbound 443/TCP to unneeded DoH servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.