Case CD2F54 · Network · L3 Applied
DNS Tunneling
Practise as: Explain it · Interview · Deep dive
Interview questionHow does DNS tunneling work, and how would you detect it?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Data is encoded in subdomain labels of queries to an attacker-controlled authoritative server; replies carry data back
- Works because internal resolvers forward queries outbound even when direct egress is blocked
- Tools: iodine, dnscat2, DNS-based C2 in Cobalt Strike; often uses TXT, NULL or CNAME records
- Detect: high label entropy, long query names, high unique-subdomain count per domain, unusual TXT volume
- Prevent: force clients to internal resolvers, block external DNS and DoH, apply protective DNS and RPZ
If the interviewer pushes back
- How does DNS over HTTPS change both the attacker and defender side of this problem?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.