1200KM / simulation
T1071.004 DNS — Attack Simulation
Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may…
Technique description
Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- DNS Large Query Volume
Procedure 1700f5d6-5a44-487b-84de-bc66f507b0a6; elevation not declared required; cleanup not declared. Not executed or individually validated.
- DNS Regular Beaconing
Procedure 3efc144e-1af8-46bb-8ca2-1376bb6db8b6; elevation not declared required; cleanup not declared. Not executed or individually validated.
- DNS C2
Procedure e7bf9802-2e78-4db9-93b5-181b7bcd37d7; elevation not declared required; cleanup not declared. Not executed or individually validated.
- DNS Long Domain Query
Procedure fef31710-223a-40ee-8462-a396d6b66978; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.