logo

How to Detect DNS Tunneling in the Network?

ID: ea3f0776-58ee-50f2-98e2-e3db45468070

STIX ID: report--ea3f0776-58ee-50f2-98e2-e3db45468070

Feed Name: Cato Networks

Threat Score
60/100

Date Published: 2021-11-02

Date Updated: 2026-07-23

Author: Zohar Buber

...
...

This report explains how attackers use DNS tunneling (including TXT and uncommon query types) for C2 and data exfiltration—citing BazarCall/BazaLoader, Anchor, and APT activity—and describes network detection techniques such as identifying long/uncommon queries, consistent algorithmic query structures, unknown/unpopular DNS destinations, and distinguishing legitimate security product traffic from bot-generated DNS traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.