DNS Over HTTPS for Cobalt Strike
ID: b85ba90d-f290-5bfe-93b6-111fec68139f
STIX ID: report--b85ba90d-f290-5bfe-93b6-111fec68139f
Feed Name: Black Hills Infosec Blog
This post explains how to run Cobalt Strike Beacon over DNS over HTTPS (DoH) using the TitanLdr user-defined reflective loader to hook DNSQuery_A and route queries through reputable DoH providers (e.g., Google, Quad9, Cloudflare, OpenDNS, HE), including a fork that randomizes among multiple resolvers, build instructions, and Cobalt Strike setup. It highlights advantages (valid SSL, no third-party infrastructure, trusted domains), tradeoffs (lower throughput due to TXT record limits, reliance on public DoH endpoints), and detection/mitigation ideas such as combining DNS monitoring with SSL inspection and blocking outbound 443/TCP to unneeded DoH servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
