logo

Waiting for goDoH

ID: fdcb5d8e-359a-5f6f-8c19-299e78e59277

STIX ID: report--fdcb5d8e-359a-5f6f-8c19-299e78e59277

Feed Name: SensePost Blog

Date Published: 2018-10-24

Date Updated: 2026-04-29

...
...

This report describes a technique for covert command-and-control and data exfiltration using DNS-over-HTTPS (DoH), demonstrated with the "godoh" proof-of-concept tool. It adapts traditional DNS tunneling to leverage HTTPS connections to trusted DoH providers (e.g., Google), enabling TXT-based tasking and A-record-based data return while complicating network monitoring and controls that rely on classic DNS visibility. The author details the agent–C2 protocol, operational workflow (encryption, encoding, chunking, control flags), performance trade-offs, and defensive considerations (e.g., split-horizon DNS, request size/rate analysis, label inspection), emphasizing the increased detection complexity when DNS is proxied over HTTPS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.